CVE-2018-1672: IBM WebSphere Portal
Medium severity, CVSS 6.3. EPSS: 1.2% chance of exploitation in the next 30 days.
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user. IBM X-Force ID: 144958.
Affected products
- IBM WebSphere Portal: version 7.0.0.0 only; version 7.0.0.1 only; version 7.0.0.2 only; version 8.0.0.0 only; version 8.0.0.1 only; version 8.5.0.0 only; …
Published 2018-10-01. Last modified 2026-06-17.