First published: Mon Oct 01 2018(Updated: )
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) installation. This can lead to security miss-configuration of the installation. IBM X-Force ID: 138950.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Portal | =7.0.0.0 | |
IBM WebSphere Portal | =7.0.0.1 | |
IBM WebSphere Portal | =7.0.0.1-cf011 | |
IBM WebSphere Portal | =7.0.0.1-cf012 | |
IBM WebSphere Portal | =7.0.0.1-cf013 | |
IBM WebSphere Portal | =7.0.0.1-cf014 | |
IBM WebSphere Portal | =7.0.0.1-cf015 | |
IBM WebSphere Portal | =7.0.0.1-cf016 | |
IBM WebSphere Portal | =7.0.0.1-cf017 | |
IBM WebSphere Portal | =7.0.0.1-cf018 | |
IBM WebSphere Portal | =7.0.0.1-cf019 | |
IBM WebSphere Portal | =7.0.0.1-cf020 | |
IBM WebSphere Portal | =7.0.0.2 | |
IBM WebSphere Portal | =7.0.0.2-cf012 | |
IBM WebSphere Portal | =7.0.0.2-cf013 | |
IBM WebSphere Portal | =7.0.0.2-cf014 | |
IBM WebSphere Portal | =7.0.0.2-cf015 | |
IBM WebSphere Portal | =7.0.0.2-cf016 | |
IBM WebSphere Portal | =7.0.0.2-cf017 | |
IBM WebSphere Portal | =7.0.0.2-cf018 | |
IBM WebSphere Portal | =7.0.0.2-cf019 | |
IBM WebSphere Portal | =7.0.0.2-cf020 | |
IBM WebSphere Portal | =7.0.0.2-cf021 | |
IBM WebSphere Portal | =7.0.0.2-cf022 | |
IBM WebSphere Portal | =7.0.0.2-cf023 | |
IBM WebSphere Portal | =7.0.0.2-cf024 | |
IBM WebSphere Portal | =7.0.0.2-cf025 | |
IBM WebSphere Portal | =7.0.0.2-cf026 | |
IBM WebSphere Portal | =7.0.0.2-cf027 | |
IBM WebSphere Portal | =7.0.0.2-cf028 | |
IBM WebSphere Portal | =7.0.0.2-cf029 | |
IBM WebSphere Portal | =7.0.0.2-cf030 | |
IBM WebSphere Portal | =8.0.0.0 | |
IBM WebSphere Portal | =8.0.0.0-cf01 | |
IBM WebSphere Portal | =8.0.0.0-cf02 | |
IBM WebSphere Portal | =8.0.0.0-cf03 | |
IBM WebSphere Portal | =8.0.0.0-cf04 | |
IBM WebSphere Portal | =8.0.0.0-cf05 | |
IBM WebSphere Portal | =8.0.0.0-cf06 | |
IBM WebSphere Portal | =8.0.0.1 | |
IBM WebSphere Portal | =8.0.0.1-cf04 | |
IBM WebSphere Portal | =8.0.0.1-cf05 | |
IBM WebSphere Portal | =8.0.0.1-cf06 | |
IBM WebSphere Portal | =8.0.0.1-cf07 | |
IBM WebSphere Portal | =8.0.0.1-cf08 | |
IBM WebSphere Portal | =8.0.0.1-cf09 | |
IBM WebSphere Portal | =8.0.0.1-cf10 | |
IBM WebSphere Portal | =8.0.0.1-cf11 | |
IBM WebSphere Portal | =8.0.0.1-cf12 | |
IBM WebSphere Portal | =8.0.0.1-cf13 | |
IBM WebSphere Portal | =8.0.0.1-cf14 | |
IBM WebSphere Portal | =8.0.0.1-cf15 | |
IBM WebSphere Portal | =8.0.0.1-cf16 | |
IBM WebSphere Portal | =8.0.0.1-cf17 | |
IBM WebSphere Portal | =8.0.0.1-cf18 | |
IBM WebSphere Portal | =8.0.0.1-cf19 | |
IBM WebSphere Portal | =8.0.0.1-cf20 | |
IBM WebSphere Portal | =8.0.0.1-cf21 | |
IBM WebSphere Portal | =8.0.0.1-cf22 | |
IBM WebSphere Portal | =8.5.0.0 | |
IBM WebSphere Portal | =8.5.0.0-cf01 | |
IBM WebSphere Portal | =8.5.0.0-cf02 | |
IBM WebSphere Portal | =8.5.0.0-cf03 | |
IBM WebSphere Portal | =8.5.0.0-cf04 | |
IBM WebSphere Portal | =8.5.0.0-cf05 | |
IBM WebSphere Portal | =8.5.0.0-cf06 | |
IBM WebSphere Portal | =8.5.0.0-cf07 | |
IBM WebSphere Portal | =8.5.0.0-cf08 | |
IBM WebSphere Portal | =8.5.0.0-cf09 | |
IBM WebSphere Portal | =8.5.0.0-cf10 | |
IBM WebSphere Portal | =8.5.0.0-cf11 | |
IBM WebSphere Portal | =8.5.0.0-cf12 | |
IBM WebSphere Portal | =8.5.0.0-cf13 | |
IBM WebSphere Portal | =8.5.0.0-cf14 | |
IBM WebSphere Portal | =8.5.0.0-cf15 | |
IBM WebSphere Portal | =9.0.0.0 | |
IBM WebSphere Portal | =9.0.0.0-cf14 | |
IBM WebSphere Portal | =9.0.0.0-cf15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1420 is rated as medium, with a score of 6.5.
To fix CVE-2018-1420, you should manually review and reapply your access control settings after performing any Combined Cumulative Fix installation.
CVE-2018-1420 affects IBM WebSphere Portal versions 7.0, 8.0, 8.5, and 9.0.
CVE-2018-1420 can lead to security misconfiguration due to the resetting of access control settings to the out-of-the-box configuration.
CVE-2018-1420 is a privilege escalation vulnerability that occurs during the installation of Combined Cumulative Fixes.