First published: Thu Dec 13 2018(Updated: )
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 150017.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Access Manager | >=9.0.1.0<=9.0.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1813 is medium, with a severity value of 6.5.
CVE-2018-1813 allows attackers to bypass application controls, resulting in direct impact to the system and data integrity.
IBM Security Access Manager Appliance versions 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 are affected by CVE-2018-1813.
To fix CVE-2018-1813, update IBM Security Access Manager Appliance to a version above 9.0.5.0.
More information about CVE-2018-1813 can be found at the following references: http://www.ibm.com/support/docview.wss?uid=ibm10787785 and https://exchange.xforce.ibmcloud.com/vulnerabilities/150017