CVE-2018-1443 vulnerability in IBM Products
Published on March 8, 2018
An XML parsing vulnerability affects IBM SAML-based single sign-on (SSO) systems (IBM Security Access Manager 9.0.0 - 9.0.4 and IBM Tivoli Federated Identity Manager 6.2 - 6.0.2.) This vulnerability can allow an attacker with authenticated access to trick SAML systems into authenticating as a different user without knowledge of the victim users password. IBM X-Force ID: 139754.
Products Associated with CVE-2018-1443
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2018-1443 are published in these products:
Affected Versions
IBM Security Access Manager:- Version 9.0.0.1 is affected.
- Version 9.0.0 is affected.
- Version 9.0.1.0 is affected.
- Version 9.0.2.0 is affected.
- Version 9.0.2.1 is affected.
- Version 9.0.3 is affected.
- Version 9.0.3.1 is affected.
- Version 9.0.4 is affected.
- Version 6.2.1 is affected.
- Version 6.2 is affected.
- Version 6.2.2 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.