CVE-2018-1851: IBM WebSphere Application Server

Critical severity, CVSS 9.8. EPSS: 3.9% chance of exploitation in the next 30 days.

IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the system, caused by improper deserialization. By sending a specially-crafted request to the RP service, an attacker could exploit this vulnerability to execute arbitrary code. IBM X-Force ID: 150999.

Affected products

  • IBM WebSphere Application Server: before 18.0.0.3 (fixed in 18.0.0.3)

Published 2018-10-31. Last modified 2026-06-17.