CVE-2018-1420: IBM WebSphere Portal

Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) installation. This can lead to security miss-configuration of the installation. IBM X-Force ID: 138950.

Affected products

  • IBM WebSphere Portal: version 7.0.0.0 only; version 7.0.0.1 only; version 7.0.0.2 only; version 8.0.0.0 only; version 8.0.0.1 only; version 8.5.0.0 only; …

Published 2018-10-01. Last modified 2026-06-17.