CVE-2018-1899

4 documents4 sources
Severity
4.3MEDIUM
EPSS
0.1%
top 76.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 5
Latest updateMay 13

Description

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an attacker to change one of the settings related to InfoSphere Business Glossary Anywhere due to improper access control. IBM X-Force ID: 152528.

CVSS vector

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

CVEListV5ibm/infosphere_information_server11.3, 11.5, 11.7+2
NVDibm/infosphere_information11.5, 11.7+1

🔴Vulnerability Details

2
GHSA
GHSA-5qgj-fmxp-hjg7: IBM InfoSphere Information Server 112022-05-13
CVEList
CVE-2018-1899: IBM InfoSphere Information Server 112019-03-05

💬Community

1
Bugzilla
CVE-2018-5968 jackson-databind: unsafe deserialization due to incomplete blacklist (incomplete fix for CVE-2017-7525 and CVE-2017-17485)2018-01-24
CVE-2018-1899 (MEDIUM CVSS 4.3) | IBM InfoSphere Information Server 1 | cvebase.io