CVE-2018-1672

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user. IBM X-Force ID: 144958.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 MEDIUM
NETWORK
HIGH
LOW
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
ibmCNA
5 MEDIUM
NETWORK
HIGH
LOW
CVSS:3.0/A:L/AC:H/AV:N/C:L/I:L/PR:L/S:U/UI:N/E:U/RC:C/RL:O
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 47%
VendorProductVersion
ibmwebsphere_portal
7.0.0.0
ibmwebsphere_portal
7.0.0.1
ibmwebsphere_portal
7.0.0.1:cf011
ibmwebsphere_portal
7.0.0.1:cf012
ibmwebsphere_portal
7.0.0.1:cf013
ibmwebsphere_portal
7.0.0.1:cf014
ibmwebsphere_portal
7.0.0.1:cf015
ibmwebsphere_portal
7.0.0.1:cf016
ibmwebsphere_portal
7.0.0.1:cf017
ibmwebsphere_portal
7.0.0.1:cf018
ibmwebsphere_portal
7.0.0.1:cf019
ibmwebsphere_portal
7.0.0.1:cf020
ibmwebsphere_portal
7.0.0.2
ibmwebsphere_portal
7.0.0.2:cf012
ibmwebsphere_portal
7.0.0.2:cf013
ibmwebsphere_portal
7.0.0.2:cf014
ibmwebsphere_portal
7.0.0.2:cf015
ibmwebsphere_portal
7.0.0.2:cf016
ibmwebsphere_portal
7.0.0.2:cf017
ibmwebsphere_portal
7.0.0.2:cf018
ibmwebsphere_portal
7.0.0.2:cf019
ibmwebsphere_portal
7.0.0.2:cf020
ibmwebsphere_portal
7.0.0.2:cf021
ibmwebsphere_portal
7.0.0.2:cf022
ibmwebsphere_portal
7.0.0.2:cf023
ibmwebsphere_portal
7.0.0.2:cf024
ibmwebsphere_portal
7.0.0.2:cf025
ibmwebsphere_portal
7.0.0.2:cf026
ibmwebsphere_portal
7.0.0.2:cf027
ibmwebsphere_portal
7.0.0.2:cf028
ibmwebsphere_portal
7.0.0.2:cf029
ibmwebsphere_portal
7.0.0.2:cf030
ibmwebsphere_portal
8.0.0.0
ibmwebsphere_portal
8.0.0.0:cf01
ibmwebsphere_portal
8.0.0.0:cf02
ibmwebsphere_portal
8.0.0.0:cf03
ibmwebsphere_portal
8.0.0.0:cf04
ibmwebsphere_portal
8.0.0.0:cf05
ibmwebsphere_portal
8.0.0.0:cf06
ibmwebsphere_portal
8.0.0.1
ibmwebsphere_portal
8.0.0.1:cf04
ibmwebsphere_portal
8.0.0.1:cf05
ibmwebsphere_portal
8.0.0.1:cf06
ibmwebsphere_portal
8.0.0.1:cf07
ibmwebsphere_portal
8.0.0.1:cf08
ibmwebsphere_portal
8.0.0.1:cf09
ibmwebsphere_portal
8.0.0.1:cf10
ibmwebsphere_portal
8.0.0.1:cf11
ibmwebsphere_portal
8.0.0.1:cf12
ibmwebsphere_portal
8.0.0.1:cf13
ibmwebsphere_portal
8.0.0.1:cf14
ibmwebsphere_portal
8.0.0.1:cf15
ibmwebsphere_portal
8.0.0.1:cf16
ibmwebsphere_portal
8.0.0.1:cf17
ibmwebsphere_portal
8.0.0.1:cf18
ibmwebsphere_portal
8.0.0.1:cf19
ibmwebsphere_portal
8.0.0.1:cf20
ibmwebsphere_portal
8.0.0.1:cf21
ibmwebsphere_portal
8.0.0.1:cf22
ibmwebsphere_portal
8.0.0.1:cf23
ibmwebsphere_portal
8.5.0.0
ibmwebsphere_portal
8.5.0.0:cf01
ibmwebsphere_portal
8.5.0.0:cf02
ibmwebsphere_portal
8.5.0.0:cf03
ibmwebsphere_portal
8.5.0.0:cf04
ibmwebsphere_portal
8.5.0.0:cf05
ibmwebsphere_portal
8.5.0.0:cf06
ibmwebsphere_portal
8.5.0.0:cf07
ibmwebsphere_portal
8.5.0.0:cf08
ibmwebsphere_portal
8.5.0.0:cf09
ibmwebsphere_portal
8.5.0.0:cf10
ibmwebsphere_portal
8.5.0.0:cf11
ibmwebsphere_portal
8.5.0.0:cf12
ibmwebsphere_portal
8.5.0.0:cf13
ibmwebsphere_portal
8.5.0.0:cf14
ibmwebsphere_portal
8.5.0.0:cf15
ibmwebsphere_portal
9.0.0.0
ibmwebsphere_portal
9.0.0.0:cf14
ibmwebsphere_portal
9.0.0.0:cf15
𝑥
= Vulnerable software versions