IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) installation. This can lead to security miss-configuration of the installation. IBM X-Force ID: 138950.
References
Link | Resource |
---|---|
https://www.ibm.com/support/docview.wss?uid=swg22014276 | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/138950 | VDB Entry Vendor Advisory |
http://www.securitytracker.com/id/1041767 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2018-10-01 07:29
Updated : 2019-10-09 16:38
NVD link : CVE-2018-1420
Mitre link : CVE-2018-1420
JSON object : View
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
Products Affected
ibm
- websphere_portal