CVE-2018-1623
Description
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 144408.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 stores web pages locally, allowing another local user to read them, leading to information disclosure.
Vulnerability
IBM Security Privileged Identity Manager Virtual Appliance version 2.2.1 stores web pages locally on the system. A local user can read these stored web pages, potentially gaining access to sensitive information. The vulnerability is present in the default configuration and requires no special conditions beyond local file system access.
Exploitation
An attacker with local access to the system can read the stored web pages by navigating to the file system location where they are saved. No authentication or user interaction is required beyond having local user privileges on the appliance. The attacker does not need to be the same user that originally accessed the web pages.
Impact
Successful exploitation allows an attacker to read the contents of locally stored web pages, which may contain sensitive information such as session tokens, credentials, or other confidential data. This results in information disclosure, compromising the confidentiality of the system. No remote code execution or privilege escalation is achieved.
Mitigation
IBM has addressed this vulnerability in a security bulletin [1] that includes fixes for multiple issues. Users should apply the latest updates provided by IBM for the IBM Security Privileged Identity Manager Virtual Appliance. No workaround is documented in the available references. The fixed version is not explicitly stated in the provided text, but the bulletin indicates that the vulnerability is resolved.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: =2.2.1
- Range: 2.1.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.ibm.com/support/docview.wssmitrex_refsource_CONFIRM
- exchange.xforce.ibmcloud.com/vulnerabilities/144408mitrevdb-entryx_refsource_XF
News mentions
0No linked articles in our index yet.