Lucene search

K
ibmIBM23DD45D20FE3FAB90A3E097AB4AF125249E58E47FAC5C7103A9F3831C7B1A1BE
HistoryNov 23, 2018 - 10:15 a.m.

Security Bulletin: Potential spoofing attack in WebSphere Application Server shipped with Jazz for Service Management (CVE-2018-1695)

2018-11-2310:15:01
www.ibm.com
10

EPSS

0.002

Percentile

64.8%

Summary

There is a potential spoofing attack in WebSphere Application Server using Form Login when using Java SE 6. This does not occur when using other versions of the Java SE.

Vulnerability Details

CVEID: CVE-2018-1695 DESCRIPTION: IBM WebSphere Application Server installations using Form Login could allow a remote attacker to conducts spoofing attacks.
CVSS Base Score: 7.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/145769&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)

Affected Products and Versions

Jazz for Service Management version 1.1.0 - 1.1.3

Remediation/Fixes

Principal Product and Version(s)

| Affected Supporting Product and Version | Affected Supporting Product Security Bulletin
—|—|—
Jazz for Service Management version 1.1.0 - 1.1.3 | Websphere Application Server Full Profile 8.5.5 |

Security Bulletin: Potential spoofing attack in WebSphere Application Server (CVE-2018-1695)

Workarounds and Mitigations

Please refer to WAS iFix

EPSS

0.002

Percentile

64.8%

Related for 23DD45D20FE3FAB90A3E097AB4AF125249E58E47FAC5C7103A9F3831C7B1A1BE