CVE-2018-1683Missing Encryption of Sensitive Data in IBM Websphere Application Server

Severity
7.5HIGHNVD
CNA5.9
EPSS
0.2%
top 61.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 26
Latest updateMay 13

Description

IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by the failure to encrypt ORB communication. IBM X-Force ID: 145455.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-r586-f347-cfhg: IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by the failure to encrypt ORB communica2022-05-13
CVEList
CVE-2018-1683: IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by the failure to encrypt ORB communica2018-09-26

💥Exploits & PoCs

1
Nuclei
PRTG Network Monitor - Local File Inclusion

💬Community

1
Bugzilla
CVE-2018-16838 sssd: improper implementation of GPOs due to too restrictive permissions2018-10-18
CVE-2018-1683 — Missing Encryption of Sensitive Data | cvebase