CVE-2018-1420

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) installation. This can lead to security miss-configuration of the installation. IBM X-Force ID: 138950.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
HIGH
LOW
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
ibmCNA
5.3 MEDIUM
NETWORK
HIGH
LOW
CVSS:3.0/A:N/AC:H/AV:N/C:N/I:H/PR:L/S:U/UI:N/E:U/RC:C/RL:O
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 37%
VendorProductVersion
ibmwebsphere_portal
7.0.0.0
ibmwebsphere_portal
7.0.0.1
ibmwebsphere_portal
7.0.0.1:cf011
ibmwebsphere_portal
7.0.0.1:cf012
ibmwebsphere_portal
7.0.0.1:cf013
ibmwebsphere_portal
7.0.0.1:cf014
ibmwebsphere_portal
7.0.0.1:cf015
ibmwebsphere_portal
7.0.0.1:cf016
ibmwebsphere_portal
7.0.0.1:cf017
ibmwebsphere_portal
7.0.0.1:cf018
ibmwebsphere_portal
7.0.0.1:cf019
ibmwebsphere_portal
7.0.0.1:cf020
ibmwebsphere_portal
7.0.0.2
ibmwebsphere_portal
7.0.0.2:cf012
ibmwebsphere_portal
7.0.0.2:cf013
ibmwebsphere_portal
7.0.0.2:cf014
ibmwebsphere_portal
7.0.0.2:cf015
ibmwebsphere_portal
7.0.0.2:cf016
ibmwebsphere_portal
7.0.0.2:cf017
ibmwebsphere_portal
7.0.0.2:cf018
ibmwebsphere_portal
7.0.0.2:cf019
ibmwebsphere_portal
7.0.0.2:cf020
ibmwebsphere_portal
7.0.0.2:cf021
ibmwebsphere_portal
7.0.0.2:cf022
ibmwebsphere_portal
7.0.0.2:cf023
ibmwebsphere_portal
7.0.0.2:cf024
ibmwebsphere_portal
7.0.0.2:cf025
ibmwebsphere_portal
7.0.0.2:cf026
ibmwebsphere_portal
7.0.0.2:cf027
ibmwebsphere_portal
7.0.0.2:cf028
ibmwebsphere_portal
7.0.0.2:cf029
ibmwebsphere_portal
7.0.0.2:cf030
ibmwebsphere_portal
8.0.0.0
ibmwebsphere_portal
8.0.0.0:cf01
ibmwebsphere_portal
8.0.0.0:cf02
ibmwebsphere_portal
8.0.0.0:cf03
ibmwebsphere_portal
8.0.0.0:cf04
ibmwebsphere_portal
8.0.0.0:cf05
ibmwebsphere_portal
8.0.0.0:cf06
ibmwebsphere_portal
8.0.0.1
ibmwebsphere_portal
8.0.0.1:cf04
ibmwebsphere_portal
8.0.0.1:cf05
ibmwebsphere_portal
8.0.0.1:cf06
ibmwebsphere_portal
8.0.0.1:cf07
ibmwebsphere_portal
8.0.0.1:cf08
ibmwebsphere_portal
8.0.0.1:cf09
ibmwebsphere_portal
8.0.0.1:cf10
ibmwebsphere_portal
8.0.0.1:cf11
ibmwebsphere_portal
8.0.0.1:cf12
ibmwebsphere_portal
8.0.0.1:cf13
ibmwebsphere_portal
8.0.0.1:cf14
ibmwebsphere_portal
8.0.0.1:cf15
ibmwebsphere_portal
8.0.0.1:cf16
ibmwebsphere_portal
8.0.0.1:cf17
ibmwebsphere_portal
8.0.0.1:cf18
ibmwebsphere_portal
8.0.0.1:cf19
ibmwebsphere_portal
8.0.0.1:cf20
ibmwebsphere_portal
8.0.0.1:cf21
ibmwebsphere_portal
8.0.0.1:cf22
ibmwebsphere_portal
8.5.0.0
ibmwebsphere_portal
8.5.0.0:cf01
ibmwebsphere_portal
8.5.0.0:cf02
ibmwebsphere_portal
8.5.0.0:cf03
ibmwebsphere_portal
8.5.0.0:cf04
ibmwebsphere_portal
8.5.0.0:cf05
ibmwebsphere_portal
8.5.0.0:cf06
ibmwebsphere_portal
8.5.0.0:cf07
ibmwebsphere_portal
8.5.0.0:cf08
ibmwebsphere_portal
8.5.0.0:cf09
ibmwebsphere_portal
8.5.0.0:cf10
ibmwebsphere_portal
8.5.0.0:cf11
ibmwebsphere_portal
8.5.0.0:cf12
ibmwebsphere_portal
8.5.0.0:cf13
ibmwebsphere_portal
8.5.0.0:cf14
ibmwebsphere_portal
8.5.0.0:cf15
ibmwebsphere_portal
9.0.0.0
ibmwebsphere_portal
9.0.0.0:cf14
ibmwebsphere_portal
9.0.0.0:cf15
𝑥
= Vulnerable software versions