CVE-2018-1623: Infoleak
Published Apr 2, 2019
·Updated
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 144408.
Affected Software
1 affected component
IBM Security Privileged Identity Manager=2.1.1
Event History
Apr 2, 2019
CVE Published
via MITRE·01:20 PM
Data Sourced
via MITRE·01:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1623?
CVE-2018-1623 is classified as a medium severity vulnerability.
2
How do I fix CVE-2018-1623?
To mitigate CVE-2018-1623, upgrade to a patched version of IBM Security Privileged Identity Manager that addresses this issue.
3
Who is affected by CVE-2018-1623?
CVE-2018-1623 affects users of IBM Security Privileged Identity Manager Virtual Appliance version 2.2.1 and earlier.
4
What type of vulnerability is CVE-2018-1623?
CVE-2018-1623 is a local file storage vulnerability that can allow unauthorized access to web pages.
5
Is there a workaround for CVE-2018-1623?
There are no specific workarounds for CVE-2018-1623; upgrading to a secure version is recommended.