CVE-2018-1904
published 2018-12-11CVE-2018-1904: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through an administrative client class with…
critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through an administrative client class with a serialized object from untrusted sources. IBM X-Force ID: 152533.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | 7.0.0.0 – 7.0.0.45 | — |
| ibm | websphere_application_server | 8.0.0.0 – 8.0.0.15 | — |
| ibm | websphere_application_server | 8.5.0.0 – 8.5.5.14 | — |
| ibm | websphere_application_server | 9.0.0.0 – 9.0.0.9 | — |