CVE-2018-1420 MEDIUM

CVE-2018-1420

Vendor Ibm
Product WebSphere Portal
Published October 1, 2018
Last update September 16, 2024

CVSS base score

5.3/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.0/A:N/AC:H/AV:N/C:N/I:H/PR:L/S:U/UI:N/E:U/RC:C/RL:O

What the vulnerability does

01Description

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) installation. This can lead to security miss-configuration of the installation. IBM X-Force ID: 138950.

Key dates

02Disclosure timeline

October 1, 2018 CVE published
September 16, 2024 Record updated