CVE-2018-1755 Information
Feb 14, 2021
cve
Description
IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information caused by incorrect transport being used when Liberty is configured to use Java Authentication SPI for Containers (JASPIC). This can happen when the Application Server is configured to permit access on non-secure (http) port and using JASPIC or JSR375 authentication.
CVSS Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
http://www.securityfocus.com/bid/105150 http://www.securitytracker.com/id/1041558 https://exchange.xforce.ibmcloud.com/vulnerabilities/148597 https://www.ibm.com/support/docview.wss?uid=ibm10728689
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
5.9
Share on: