| Vulnerability Name: | CVE-2018-1755 (CCN-148597) | ||||||||||||
| Assigned: | 2017-12-13 | ||||||||||||
| Published: | 2018-08-22 | ||||||||||||
| Updated: | 2019-10-09 | ||||||||||||
| Summary: | IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by incorrect transport being used when Liberty is configured to use Java Authentication SPI for Containers (JASPIC). This can happen when the Application Server is configured to permit access on non-secure (http) port and using JASPIC or JSR375 authentication. | ||||||||||||
| CVSS v3 Severity: | 5.9 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N) 5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
| ||||||||||||
| Vulnerability Type: | CWE-200 | ||||||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2018-1755 Source: BID Type: Third Party Advisory, VDB Entry 105150 Source: CCN Type: BID-105150 IBM WebSphere Application Server Liberty CVE-2018-1755 Information Disclosure Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1041558 Source: XF Type: UNKNOWN ibm-websphere-cve20181755-info-disc(148597) Source: XF Type: VDB Entry, Vendor Advisory ibm-websphere-cve20181755-info-disc(148597) Source: CCN Type: IBM Security Bulletin 0728689 (WebSphere Application Server) Information disclosure in WebSphere Application Server Liberty (CVE-2018-1755) Source: CONFIRM Type: Patch, Vendor Advisory https://www.ibm.com/support/docview.wss?uid=ibm10728689 Source: CCN Type: IBM Security Bulletin 732916 (Liberty for Java for Bluemix) Multiple security vulnerabilities affect Liberty for Java for IBM Cloud Source: CCN Type: IBM Security Bulletin 734167 (WebSphere Application Server in Cloud) Multiple security vulnerabilities affect IBM WebSphere Application Server in IBM Cloud Source: CCN Type: IBM Security Bulletin 0743011 (Endpoint Manager for Lifecycle Management) Server Automation is affected by the following vulnerabilities exposures (CVE-2018-8039, CVE-2018-1683, CVE-2018-1755) Source: CCN Type: IBM Security Bulletin 957891 (Cloud Private) A Security Vulnerability affects IBM Cloud Private - IAM WebSphere Liberty (CVE-2018-1683, CVE-2018-1755) | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||