vulnerability
IBM WebSphere Application Server: CVE-2018-1614: Information disclosure in WebSphere Application Server with SAML (CVE-2018-1614)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:L/Au:N/C:P/I:N/A:N) | Jun 26, 2018 | Jun 28, 2018 | Aug 11, 2025 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
Jun 26, 2018
Added
Jun 28, 2018
Modified
Aug 11, 2025
Description
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using malformed SAML responses from the SAML identity provider could allow a remote attacker to obtain sensitive information. IBM X-Force ID: 144270.
Solutions
ibm-was-install-8-0-0-0-pi78804ibm-was-install-8-5-0-0-pi78804ibm-was-install-9-0-0-0-pi78804ibm-was-upgrade-8-5-0-0-8-5-5-14ibm-was-upgrade-9-0-0-0-9-0-0-9
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.