CVE-2018-1722
10.0
CRITICAL · CVSS 3.0 · EPSS 9% (pctl 95)
In your normal cycle
Critical by CVSS (10), but no sign of active exploitation.
Description
IBM Security Access Manager Appliance 9.0.4.0 and 9.0.5.0 could allow remote code execution when Advanced Access Control or Federation services are running. IBM X-Force ID: 147370.
Scoring
| CVSS | 10.0 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 9.04% — more likely to be exploited than 95% of all CVEs |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-08-24 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| ibm | security access manager |
References
- http://www.securityfocus.com/bid/105145
- http://www.securitytracker.com/id/1041557
- https://exchange.xforce.ibmcloud.com/vulnerabilities/147370
- https://www.ibm.com/support/docview.wss?uid=ibm10719623
- http://www.securityfocus.com/bid/105145
- http://www.securitytracker.com/id/1041557
- https://exchange.xforce.ibmcloud.com/vulnerabilities/147370
- https://www.ibm.com/support/docview.wss?uid=ibm10719623
→ the Explorer · watch your stack · NVD