CVE-2018-1999Sensitive Information Exposure in IBM Business Process Manager

Severity
4.3MEDIUMNVD
EPSS
0.1%
top 69.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 8
Latest updateMay 13

Description

IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could reveal sensitive version information about the server from error pages that could aid an attacker in further attacks against the system. IBM X-Force ID: 154889.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

CVEListV5ibm/business_automation_workflow18.0.0.0, 18.0.0.1, 18.0.0.2+2
NVDibm/business_automation_workflow18.0.0.0, 18.0.0.1, 18.0.0.2+2
NVDibm/business_process_manager8.0.0.08.0.1.3+5

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9pp4-qqcw-c8m5: IBM Business Automation Workflow 182022-05-13
CVEList
CVE-2018-1999: IBM Business Automation Workflow 182019-04-08

💥Exploits & PoCs

1
Exploit-DB
DEWESoft X3 SP1 (x64) - Remote Command Execution2018-03-12
CVE-2018-1999 — Sensitive Information Exposure in IBM | cvebase