CVE-2018-1946 MEDIUM

CVE-2018-1946

Vendor Ibm
Product Security Identity Governance and Intelligence
Published February 21, 2019
Last update September 16, 2024

CVSS base score

5.9/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.0/A:N/AC:H/AV:N/C:H/I:N/PR:N/S:U/UI:N/E:U/RC:C/RL:O

What the vulnerability does

01Description

IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties. IBM X-Force ID: 153388.

Key dates

02Disclosure timeline

February 21, 2019 CVE published
September 16, 2024 Record updated