CVE-2018-1941Improper Privilege Management in IBM Campaign

Severity
7.8HIGHNVD
CNA8.4
EPSS
0.0%
top 92.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 5
Latest updateMay 13

Description

IBM Campaign 9.1.0 and 9.1.2 could allow a local user to obtain admini privileges due to the application not validating access permissions. IBM X-Force ID: 153382.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDibm/campaign9.1.09.1.0.13+1
CVEListV5ibm/campaign9.1.0, 9.1.2+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-cg95-95jv-q4qm: IBM Campaign 92022-05-13
CVEList
CVE-2018-1941: IBM Campaign 92018-12-05
CVE-2018-1941 — Improper Privilege Management in IBM | cvebase