First published: Fri Sep 14 2018(Updated: )
IBM Connections 5.0, 5.5, and 6.0 is vulnerable to an External Service Interaction attack, caused by improper validation of a request property. By submitting suitable payloads, an attacker could exploit this vulnerability to induce the Connections server to attack other systems. IBM X-Force ID: 148946.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Connections | =5.0 | |
IBM Connections | =5.5 | |
IBM Connections | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1791 is medium with a severity value of 4.9.
CVE-2018-1791 affects IBM Connections versions 5.0, 5.5, and 6.0.
An External Service Interaction attack is a vulnerability that allows an attacker to exploit a server to attack other systems.
CVE-2018-1791 is classified as CWE-20, which is Improper Input Validation.
You can find more information about CVE-2018-1791 on the IBM X-Force ID: 148946 and the IBM support website.