ZeroHour

CVE-2018-1420

CVSS 3.0
6.5 medium
EPSS
1%p70
Published
()
Modified
Description

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) installation. This can lead to security miss-configuration of the installation. IBM X-Force ID: 138950.

Vendors
ibm
Products
websphere portal
Weakness
CWE-732
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.