CVE-2018-1851

Description

IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the system, caused by improper deserialization. By sending a specially-crafted request to the RP service, an attacker could exploit this vulnerability to execute arbitrary code. IBM X-Force ID: 150999.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
3.826

Associated Vulnerability

VulnerabilityOS Platform
Update websphere_application_server 8.5.5.9 to latest versionWindows
Update Mozilla Firefox (67.0) fixes multiple vulnerabilitesWindows
Update Mozilla Firefox (x64) (67.0) fixes multiple vulnerabilitesWindows
Update Mozilla Firefox ESR (60.7.0) fixes multiple vulnerabilitesWindows
Update Mozilla Firefox ESR (x64) (60.7.0) fixes multiple vulnerabilitesWindows
Update Mozilla Thunderbird (60.7.0) fixes multiple vulnerabilitesWindows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-309861Mozilla Firefox (67.0)
PATCH-309862Mozilla Firefox (x64) (67.0)
PATCH-309865Mozilla Firefox ESR (60.7.0)
PATCH-309867Mozilla Firefox ESR (x64) (60.7.0)
PATCH-309864Mozilla Thunderbird (60.7.0)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234