First published: Tue Jun 05 2018(Updated: )
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 140089.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Information Analyzer | =11.3 | |
IBM InfoSphere Information Analyzer | =11.5 | |
IBM InfoSphere Information Analyzer | =11.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1454 is considered a medium severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2018-1454, ensure that HTTP Strict Transport Security is properly enabled on your IBM InfoSphere Information Server installations.
CVE-2018-1454 affects IBM InfoSphere Information Server versions 11.3, 11.5, and 11.7.
The impact of CVE-2018-1454 is that it allows remote attackers to perform man-in-the-middle attacks and obtain sensitive information.
Currently, the recommended method to mitigate CVE-2018-1454 is to apply the proper configuration of HTTP Strict Transport Security.