CVE-2018-1840: IBM WebSphere Application Server
High severity, CVSS 8.1. EPSS: 2.1% chance of exploitation in the next 30 days.
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to gain elevated privileges on the system, caused when a security domain is configured to use a federated repository other than global federated repository and then migrated to a newer release of WebSphere Application Server. IBM X-Force ID: 150813.
Affected products
- IBM WebSphere Application Server: from 8.5.0.0, up to and including 8.5.5.14; from 9.0.0.0, up to and including 9.0.0.9
Published 2018-12-03. Last modified 2026-06-17.