CVE-2018-1695: High severity IBM WebSphere Application Server Feature Pack for Web Services vulnerability
Published Sep 6, 2018
·Updated
IBM WebSphere Application Server 7.0, 8.0, and 8.5.5 installations using Form Login could allow a remote attacker to conduct spoofing attacks. IBM X-Force ID: 145769.
Affected Software
3 affected components
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.0
IBM WebSphere Application Server Feature Pack for Web Services=8.0.0.0
IBM WebSphere Application Server Feature Pack for Web Services=8.5.5.0
Remediation
Patch Available
Event History
Sep 6, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1695?
CVE-2018-1695 is considered a moderate severity vulnerability due to its potential to allow spoofing attacks.
2
How do I fix CVE-2018-1695?
To fix CVE-2018-1695, update your IBM WebSphere Application Server to the latest patched version provided by IBM.
3
Who is affected by CVE-2018-1695?
CVE-2018-1695 affects installations of IBM WebSphere Application Server 7.0, 8.0, and 8.5.5 using Form Login.
4
What type of vulnerability is CVE-2018-1695?
CVE-2018-1695 is a spoofing vulnerability that could allow remote attackers to impersonate legitimate users.
5
When was CVE-2018-1695 disclosed?
CVE-2018-1695 was disclosed in 2018, specifically affecting applications that utilize the Form Login function.