Vulnerability CVE-2018-1813


Published: 2018-12-13

Description:
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 150017.

Type:

CWE-noinfo

CVSS2 => (AV:N/AC:L/Au:S/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4/10
2.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
IBM -> Security access manager 

 References:
http://www.ibm.com/support/docview.wss?uid=ibm10787785
https://exchange.xforce.ibmcloud.com/vulnerabilities/150017

Copyright 2024, cxsecurity.com

 

Back to Top