CVE-2018-1614: Infoleak
Published Jun 26, 2018
·Updated
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using malformed SAML responses from the SAML identity provider could allow a remote attacker to obtain sensitive information. IBM X-Force ID: 144270.
Affected Software
4 affected components
IBM WebSphere Application Server Feature Pack for Web Services=7.0
IBM WebSphere Application Server Feature Pack for Web Services=8.0
IBM WebSphere Application Server Feature Pack for Web Services=8.5
IBM WebSphere Application Server Feature Pack for Web Services=9.0
Event History
Jun 26, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1614?
CVE-2018-1614 is classified as a medium severity vulnerability allowing remote attackers to obtain sensitive information.
2
How do I fix CVE-2018-1614?
To mitigate CVE-2018-1614, upgrade IBM WebSphere Application Server to a version that addresses this vulnerability.
3
What versions of IBM WebSphere Application Server are affected by CVE-2018-1614?
CVE-2018-1614 affects IBM WebSphere Application Server versions 7.0, 8.0, 8.5, and 9.0.
4
What type of attack does CVE-2018-1614 exploit?
CVE-2018-1614 exploits the processing of malformed SAML responses from the SAML identity provider.
5
Can CVE-2018-1614 lead to data breaches?
Yes, CVE-2018-1614 can potentially lead to data breaches by allowing unauthorized access to sensitive information.