Vulnerability Description
IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system. By crafting a command line sent via the shared memory IPC, which could be tricked into executing an executable chosen by the attacker. IBM X-Force ID: 138708.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Notes | 8.5.1.5 |
| Ibm | Client Application Access | 1.0.0.1 |
References
- http://www.ibm.com/support/docview.wss?uid=swg22010766Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22010767Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/138708VDB Entry
- http://www.ibm.com/support/docview.wss?uid=swg22010766Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22010767Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/138708VDB Entry
FAQ
What is CVE-2018-1409?
CVE-2018-1409 is a vulnerability with a CVSS score of 7.8 (HIGH). IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system. By crafting a command line sent via the shared memory IPC, which could b...
How severe is CVE-2018-1409?
CVE-2018-1409 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-1409?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Notes, Ibm Client Application Access.