MEDIUM · 6.7

CVE-2018-1928

IBM StoredIQ 7.6.0 does not implement proper authorization of user roles due to which it was possible for a low privileged user to access the application endpoints of high privileged users and also pe...

Vulnerability Description

IBM StoredIQ 7.6.0 does not implement proper authorization of user roles due to which it was possible for a low privileged user to access the application endpoints of high privileged users and also perform some state changing actions restricted to a high privileged user. IBM X-Force ID: 153119.

CVSS Score

6.7

MEDIUM

CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
IbmStorediq>= 7.6.0.0, < 7.6.0.17

References

FAQ

What is CVE-2018-1928?

CVE-2018-1928 is a vulnerability with a CVSS score of 6.7 (MEDIUM). IBM StoredIQ 7.6.0 does not implement proper authorization of user roles due to which it was possible for a low privileged user to access the application endpoints of high privileged users and also pe...

How severe is CVE-2018-1928?

CVE-2018-1928 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-1928?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Storediq.