CVE-2018-1926: CSRF
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading a user to visit a malicious URL, a remote attacker could send a specially-crafted request. An attacker could exploit this vulnerability to perform CSRF attack and update available applications. IBM X-Force ID: 152992.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1926?
CVE-2018-1926 is classified as a moderate severity vulnerability due to its potential for cross-site request forgery.
How do I fix CVE-2018-1926?
To fix CVE-2018-1926, it is recommended to update to a patched version of IBM WebSphere Application Server.
Which versions of IBM WebSphere Application Server are affected by CVE-2018-1926?
CVE-2018-1926 affects IBM WebSphere Application Server versions 7.0, 8.0, 8.5, and 9.0 up to specific update levels.
What type of attack does CVE-2018-1926 expose users to?
CVE-2018-1926 exposes users to cross-site request forgery attacks due to improper validation of user input.
Is user interaction required for exploiting CVE-2018-1926?
Yes, exploiting CVE-2018-1926 requires user interaction, specifically persuading users to visit a malicious URL.