CVE-2018-1998: OS Command Injection
Published Mar 11, 2019
·Updated
IBM WebSphere MQ 8.0.0.0 through 9.1.1 could allow a local user to inject code that could be executed with root privileges. This is due to an incomplete fix for CVE-2018-1792. IBM X-ForceID: 154887.
Affected Software
3 affected components
IBM WebSphere MQ>=8.0.0.0<=8.0.0.10
IBM WebSphere MQ>=9.0.0.0<=9.0.0.5
IBM WebSphere MQ>=9.1.0.0<=9.1.0.1
Remediation
Patch Available
Event History
Mar 11, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2018-1998?
CVE-2018-1998 is a vulnerability in IBM WebSphere MQ that allows a local user to inject code and execute it with root privileges.
2
How severe is CVE-2018-1998?
CVE-2018-1998 has a severity score of 7.8 out of 10.
3
Which versions of IBM WebSphere MQ are affected by CVE-2018-1998?
IBM WebSphere MQ versions 8.0.0.0 to 8.0.0.10, 9.0.0.0 to 9.0.0.5, and 9.1.0.0 to 9.1.0.1 are affected by CVE-2018-1998.
4
What is the CVE ID for the incomplete fix related to CVE-2018-1998?
The incomplete fix related to CVE-2018-1998 is CVE-2018-1792.
5
How can I fix CVE-2018-1998?
To fix CVE-2018-1998, upgrade IBM WebSphere MQ to a version that includes a complete fix for the vulnerability.