CVE-2018-1901
published 2018-12-12CVE-2018-1901: IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to temporarily gain elevated privileges on the system, caused by incorrect cached…
PriorityP347high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
1.50%
71.7th percentile
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to temporarily gain elevated privileges on the system, caused by incorrect cached value being used. IBM X-Force ID: 152530.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | 8.5.0.0 – 8.5.5.14 | — |
| ibm | websphere_application_server | 9.0.0.0 – 9.0.0.9 | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
ghsa6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenRefine vulnerable to zip slip in project import
ghsa·2023-07-18·CVSS 6.5
CVE-2023-37476 [MEDIUM] CWE-22 OpenRefine vulnerable to zip slip in project import
OpenRefine vulnerable to zip slip in project import
### Impact
A carefully crafted malicious OpenRefine project tar file can be used to trigger arbitrary code execution if a user can be convinced to import it.
### Patches
The vulnerability exists in all versions of OpenRefine up to and including 3.7.3. Users should update to OpenRefine 3.7.4 as soon as possible.
### Workarounds
Only import OpenRefine projects from trusted sources.
### References
A similar [issue](https://github.com/OpenRefine/OpenRefine/issues/1840) existed in the Create Project feature ([CVE-2018-19859](https://nvd.nist.gov/vuln/detail/CVE-2018-19859)), which was fixed by PR [#1901](https://github.com/OpenRefine/OpenRefine/pull/1901).
GHSA
GHSA-6prc-5h7w-v36v: IBM WebSphere Application Server 8
ghsa_unreviewed·2022-05-13
CVE-2018-1901 [HIGH] GHSA-6prc-5h7w-v36v: IBM WebSphere Application Server 8
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to temporarily gain elevated privileges on the system, caused by incorrect cached value being used. IBM X-Force ID: 152530.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-12-12
Published