Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-1437


IBM Notes 8.5 and 9.0 could allow an attacker to execute arbitrary code on the system, caused by an error related to multiple untrusted search path. A local attacker could exploit this vulnerability to DLL hijacking to execute arbitrary code on the system or cause the application to crash. IBM X-Force ID: 139565.


Published

2018-03-14T00:29:00.373

Last Modified

2024-11-21T03:59:49.130

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 7.8 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.6

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-426

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm notes 8.5 Yes
Application ibm notes 8.5.0.2 Yes
Application ibm notes 8.5.1 Yes
Application ibm notes 8.5.1.5 Yes
Application ibm notes 8.5.2 Yes
Application ibm notes 8.5.2.4 Yes
Application ibm notes 8.5.3 Yes
Application ibm notes 8.5.3.6 Yes
Application ibm notes 9.0 Yes
Application ibm notes 9.0.1 Yes
Application ibm notes 9.0.1.9 Yes

References