Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-1899


IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an attacker to change one of the settings related to InfoSphere Business Glossary Anywhere due to improper access control. IBM X-Force ID: 152528.


Published

2019-03-05T18:29:00.353

Last Modified

2024-11-21T04:00:33.837

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 4.3 (MEDIUM)

CVSSv2 Vector

AV:A/AC:L/Au:N/C:N/I:P/A:N

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

6.5

Impact Score

2.9

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm infosphere_information_governance_catalog 11.3 Yes
Application ibm infosphere_information_governance_catalog 11.5 Yes
Application ibm infosphere_information_governance_catalog 11.7 Yes
Application ibm infosphere_information_server_on_cloud 11.5 Yes
Application ibm infosphere_information_server_on_cloud 11.7 Yes

References