First published: Tue Sep 04 2018(Updated: )
IBM WebSphere Application Server 7.0, 8.0, and 8.5.5 installations using Form Login could allow a remote attacker to conduct spoofing attacks. IBM X-Force ID: 145769.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1695 is considered a moderate severity vulnerability due to its potential to allow spoofing attacks.
To fix CVE-2018-1695, update your IBM WebSphere Application Server to the latest patched version provided by IBM.
CVE-2018-1695 affects installations of IBM WebSphere Application Server 7.0, 8.0, and 8.5.5 using Form Login.
CVE-2018-1695 is a spoofing vulnerability that could allow remote attackers to impersonate legitimate users.
CVE-2018-1695 was disclosed in 2018, specifically affecting applications that utilize the Form Login function.