CVE-2018-1885: Infoleak
Published Apr 8, 2019
·Updated
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could allow an unauthenticated attacker to obtain sensitve information using a specially cracted HTTP request. IBM X-Force ID: 152020.
Affected Software
16 affected components
IBM Business Automation Workflow=18.0.0.0
IBM Business Automation Workflow=18.0.0.1
IBM Business Automation Workflow=18.0.0.2
IBM Business Process Manager>=7.5.0.0<=7.5.1.2
IBM Business Process Manager>=8.0.0.0<=8.0.1.3
IBM Business Process Manager>=8.5.0.0<=8.5.0.2
IBM Business Process Manager=8.5.5.0
IBM Business Process Manager=8.5.6.0
IBM Business Process Manager=8.5.6.0-cf1
IBM Business Process Manager=8.5.6.0-cf2
IBM Business Process Manager=8.5.7.0
IBM Business Process Manager=8.5.7.0-cf2017.06
IBM Business Process Manager=8.6.0.0
IBM Business Process Manager=8.6.0.0-cf2018.03
IBM Business Process Manager Enterprise Service Bus=8.6
IBM WebSphere Enterprise Service Bus>=7.0.0.0<=7.5.1.2
Remediation
Patch Available
Event History
Apr 8, 2019
CVE Published
via MITRE·02:50 PM
Data Sourced
via MITRE·02:50 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1885?
The severity of CVE-2018-1885 is medium with a CVSS score of 5.3.
2
How can an attacker exploit CVE-2018-1885?
An unauthenticated attacker can exploit CVE-2018-1885 by sending a specially crafted HTTP request to obtain sensitive information.
3
Which versions of IBM Business Automation Workflow are affected by CVE-2018-1885?
IBM Business Automation Workflow versions 18.0.0.0, 18.0.0.1, and 18.0.0.2 are affected by CVE-2018-1885.
4
What is the CWE category of CVE-2018-1885?
CVE-2018-1885 belongs to the CWE category 200 (Information Exposure).
5
Where can I find more information about CVE-2018-1885?
You can find more information about CVE-2018-1885 at the following references: [1] [2] [3]