First published: Thu Nov 29 2018(Updated: )
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to gain elevated privileges on the system, caused when a security domain is configured to use a federated repository other than global federated repository and then migrated to a newer release of WebSphere Application Server. IBM X-Force ID: 150813.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server Feature Pack for Web Services | >=8.5.0.0<=8.5.5.14 | |
IBM WebSphere Application Server Feature Pack for Web Services | >=9.0.0.0<=9.0.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1840 has been rated as a medium severity vulnerability.
CVE-2018-1840 allows a remote attacker to gain elevated privileges on systems using a non-global federated repository.
To fix CVE-2018-1840, ensure that the security domain is configured to use the global federated repository.
CVE-2018-1840 affects IBM WebSphere Application Server versions 8.5.0.0 to 8.5.5.14 and 9.0.0.0 to 9.0.0.9.
Yes, IBM provides documentation detailing mitigations and remediation steps for CVE-2018-1840.