CVE-2018-1917: Infoleak
Published Apr 2, 2019
·Updated
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an authenticated user to access JSP files and disclose sensitive information. IBM X-Force ID: 152784.
Affected Software
5 affected components
IBM InfoSphere Information Server=11.3
IBM InfoSphere Information Server=11.5
IBM InfoSphere Information Server=11.7
IBM Infosphere Information Server On Cloud=11.5
IBM Infosphere Information Server On Cloud=11.7
Event History
Apr 2, 2019
CVE Published
via MITRE·01:20 PM
Data Sourced
via MITRE·01:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1917?
The severity of CVE-2018-1917 is medium.
2
How does CVE-2018-1917 affect IBM InfoSphere Information Server?
CVE-2018-1917 allows an authenticated user to access JSP files and disclose sensitive information on IBM InfoSphere Information Server 11.3, 11.5, and 11.7.
3
Which versions of IBM InfoSphere Information Server are affected by CVE-2018-1917?
CVE-2018-1917 affects IBM InfoSphere Information Server versions 11.3, 11.5, and 11.7.
4
Can an authenticated user exploit CVE-2018-1917?
Yes, an authenticated user can exploit CVE-2018-1917 to access JSP files and disclose sensitive information.
5
How can I mitigate CVE-2018-1917 on IBM InfoSphere Information Server?
To mitigate CVE-2018-1917 on IBM InfoSphere Information Server, apply the necessary security patches or updates provided by IBM.