CVE-2018-1840: High severity IBM WebSphere Application Server Feature Pack for Web Services vulnerability
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to gain elevated privileges on the system, caused when a security domain is configured to use a federated repository other than global federated repository and then migrated to a newer release of WebSphere Application Server. IBM X-Force ID: 150813.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1840?
CVE-2018-1840 has been rated as a medium severity vulnerability.
How does CVE-2018-1840 affect IBM WebSphere Application Server?
CVE-2018-1840 allows a remote attacker to gain elevated privileges on systems using a non-global federated repository.
How do I fix CVE-2018-1840?
To fix CVE-2018-1840, ensure that the security domain is configured to use the global federated repository.
Which versions of IBM WebSphere Application Server are affected by CVE-2018-1840?
CVE-2018-1840 affects IBM WebSphere Application Server versions 8.5.0.0 to 8.5.5.14 and 9.0.0.0 to 9.0.0.9.
Is there a solution provided for CVE-2018-1840?
Yes, IBM provides documentation detailing mitigations and remediation steps for CVE-2018-1840.