PT-2018-12347 · Ibm · Ibm Websphere Portal

Published

2018-10-01

·

Updated

2019-10-09

·

CVE-2018-1420

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions IBM WebSphere Portal versions 7.0 through 9.0
Description The issue concerns a security miss-configuration that occurs during the installation of Combined Cumulative Fix (CF) in IBM WebSphere Portal, where access control settings are reset to their out-of-the-box configuration.
Recommendations For versions 7.0 through 9.0, after installing the Combined Cumulative Fix, manually review and reapply the necessary access control settings to ensure the security configuration is properly set up.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1420

Affected Products

Ibm Websphere Portal