CVE-2018-1722
CRITICAL
10.0
CVSS 3.0
Description
IBM Security Access Manager Appliance 9.0.4.0 and 9.0.5.0 could allow remote code execution when Advanced Access Control or Federation services are running. IBM X-Force ID: 147370.
Metadata
Severity & Metrics
10.0
CRITICAL CVSS 3.0
CVSS:3.0/A:H/AC:L/AV:N/C:H/I:H/PR:N/S:C/UI:N/E:U/RC:C/RL:O
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| IBM | Security Access Manager Appliance | — | 9.0.4.0, 9.0.5.0 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | Gain Access |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 10.0 | CRITICAL | 3.0 | cna | CVSS:3.0/A:H/AC:L/AV:N/C:H/I:H/PR:N/S:C/UI:N/E:U/RC:C/RL:O |
References (4)
- https://www.ibm.com/support/docview.wss?uid=ibm10719623
- 1041557 http://www.securitytracker.com/id/1041557
- 105145 http://www.securityfocus.com/bid/105145
- ibm-sam-cve20181722-code-exec(147370) https://exchange.xforce.ibmcloud.com/vulnerabilities/147370