CVE-2018-1901: High severity ibm websphere application server feature pack for web services vulnerability
Published Dec 12, 2018
·Updated
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to temporarily gain elevated privileges on the system, caused by incorrect cached value being used. IBM X-Force ID: 152530.
Affected Software
2 affected components
IBM WebSphere Application Server Feature Pack for Web Services>=8.5.0.0<=8.5.5.14
IBM WebSphere Application Server Feature Pack for Web Services>=9.0.0.0<=9.0.0.9
Remediation
Patch Available
Event History
Dec 10, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1901?
CVE-2018-1901 is considered a moderate severity vulnerability due to the potential for remote privilege escalation.
2
How do I fix CVE-2018-1901?
To fix CVE-2018-1901, update IBM WebSphere Application Server to version 8.5.5.15 or 9.0.0.10 or later.
3
What systems are affected by CVE-2018-1901?
CVE-2018-1901 affects IBM WebSphere Application Server versions 8.5.0.0 to 8.5.5.14 and 9.0.0.0 to 9.0.0.9.
4
Can CVE-2018-1901 be exploited remotely?
Yes, CVE-2018-1901 can be exploited remotely, allowing attackers to gain elevated privileges.
5
Who discovered CVE-2018-1901?
CVE-2018-1901 was identified and reported by IBM X-Force.