CVE-2018-1420
01.10.2018, 14:29
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) installation. This can lead to security miss-configuration of the installation. IBM X-Force ID: 138950.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | websphere_portal | 7.0.0.0 |
ibm | websphere_portal | 7.0.0.1 |
ibm | websphere_portal | 7.0.0.1:cf011 |
ibm | websphere_portal | 7.0.0.1:cf012 |
ibm | websphere_portal | 7.0.0.1:cf013 |
ibm | websphere_portal | 7.0.0.1:cf014 |
ibm | websphere_portal | 7.0.0.1:cf015 |
ibm | websphere_portal | 7.0.0.1:cf016 |
ibm | websphere_portal | 7.0.0.1:cf017 |
ibm | websphere_portal | 7.0.0.1:cf018 |
ibm | websphere_portal | 7.0.0.1:cf019 |
ibm | websphere_portal | 7.0.0.1:cf020 |
ibm | websphere_portal | 7.0.0.2 |
ibm | websphere_portal | 7.0.0.2:cf012 |
ibm | websphere_portal | 7.0.0.2:cf013 |
ibm | websphere_portal | 7.0.0.2:cf014 |
ibm | websphere_portal | 7.0.0.2:cf015 |
ibm | websphere_portal | 7.0.0.2:cf016 |
ibm | websphere_portal | 7.0.0.2:cf017 |
ibm | websphere_portal | 7.0.0.2:cf018 |
ibm | websphere_portal | 7.0.0.2:cf019 |
ibm | websphere_portal | 7.0.0.2:cf020 |
ibm | websphere_portal | 7.0.0.2:cf021 |
ibm | websphere_portal | 7.0.0.2:cf022 |
ibm | websphere_portal | 7.0.0.2:cf023 |
ibm | websphere_portal | 7.0.0.2:cf024 |
ibm | websphere_portal | 7.0.0.2:cf025 |
ibm | websphere_portal | 7.0.0.2:cf026 |
ibm | websphere_portal | 7.0.0.2:cf027 |
ibm | websphere_portal | 7.0.0.2:cf028 |
ibm | websphere_portal | 7.0.0.2:cf029 |
ibm | websphere_portal | 7.0.0.2:cf030 |
ibm | websphere_portal | 8.0.0.0 |
ibm | websphere_portal | 8.0.0.0:cf01 |
ibm | websphere_portal | 8.0.0.0:cf02 |
ibm | websphere_portal | 8.0.0.0:cf03 |
ibm | websphere_portal | 8.0.0.0:cf04 |
ibm | websphere_portal | 8.0.0.0:cf05 |
ibm | websphere_portal | 8.0.0.0:cf06 |
ibm | websphere_portal | 8.0.0.1 |
ibm | websphere_portal | 8.0.0.1:cf04 |
ibm | websphere_portal | 8.0.0.1:cf05 |
ibm | websphere_portal | 8.0.0.1:cf06 |
ibm | websphere_portal | 8.0.0.1:cf07 |
ibm | websphere_portal | 8.0.0.1:cf08 |
ibm | websphere_portal | 8.0.0.1:cf09 |
ibm | websphere_portal | 8.0.0.1:cf10 |
ibm | websphere_portal | 8.0.0.1:cf11 |
ibm | websphere_portal | 8.0.0.1:cf12 |
ibm | websphere_portal | 8.0.0.1:cf13 |
ibm | websphere_portal | 8.0.0.1:cf14 |
ibm | websphere_portal | 8.0.0.1:cf15 |
ibm | websphere_portal | 8.0.0.1:cf16 |
ibm | websphere_portal | 8.0.0.1:cf17 |
ibm | websphere_portal | 8.0.0.1:cf18 |
ibm | websphere_portal | 8.0.0.1:cf19 |
ibm | websphere_portal | 8.0.0.1:cf20 |
ibm | websphere_portal | 8.0.0.1:cf21 |
ibm | websphere_portal | 8.0.0.1:cf22 |
ibm | websphere_portal | 8.5.0.0 |
ibm | websphere_portal | 8.5.0.0:cf01 |
ibm | websphere_portal | 8.5.0.0:cf02 |
ibm | websphere_portal | 8.5.0.0:cf03 |
ibm | websphere_portal | 8.5.0.0:cf04 |
ibm | websphere_portal | 8.5.0.0:cf05 |
ibm | websphere_portal | 8.5.0.0:cf06 |
ibm | websphere_portal | 8.5.0.0:cf07 |
ibm | websphere_portal | 8.5.0.0:cf08 |
ibm | websphere_portal | 8.5.0.0:cf09 |
ibm | websphere_portal | 8.5.0.0:cf10 |
ibm | websphere_portal | 8.5.0.0:cf11 |
ibm | websphere_portal | 8.5.0.0:cf12 |
ibm | websphere_portal | 8.5.0.0:cf13 |
ibm | websphere_portal | 8.5.0.0:cf14 |
ibm | websphere_portal | 8.5.0.0:cf15 |
ibm | websphere_portal | 9.0.0.0 |
ibm | websphere_portal | 9.0.0.0:cf14 |
ibm | websphere_portal | 9.0.0.0:cf15 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References