First published: Tue Apr 02 2019(Updated: )
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 144408.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Privileged Identity Manager | =2.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1623 is classified as a medium severity vulnerability.
To mitigate CVE-2018-1623, upgrade to a patched version of IBM Security Privileged Identity Manager that addresses this issue.
CVE-2018-1623 affects users of IBM Security Privileged Identity Manager Virtual Appliance version 2.2.1 and earlier.
CVE-2018-1623 is a local file storage vulnerability that can allow unauthorized access to web pages.
There are no specific workarounds for CVE-2018-1623; upgrading to a secure version is recommended.