First published: Wed Dec 12 2018(Updated: )
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to temporarily gain elevated privileges on the system, caused by incorrect cached value being used. IBM X-Force ID: 152530.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server Feature Pack for Web Services | >=8.5.0.0<=8.5.5.14 | |
IBM WebSphere Application Server Feature Pack for Web Services | >=9.0.0.0<=9.0.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1901 is considered a moderate severity vulnerability due to the potential for remote privilege escalation.
To fix CVE-2018-1901, update IBM WebSphere Application Server to version 8.5.5.15 or 9.0.0.10 or later.
CVE-2018-1901 affects IBM WebSphere Application Server versions 8.5.0.0 to 8.5.5.14 and 9.0.0.0 to 9.0.0.9.
Yes, CVE-2018-1901 can be exploited remotely, allowing attackers to gain elevated privileges.
CVE-2018-1901 was identified and reported by IBM X-Force.