CVE-2018-1822 - CVE House
Back to Database
Status published Critical CVE-2018-1822

IBM FlashSystem 900 product GUI allows a specially crafted attack...

Vulnerability Description

IBM FlashSystem 900 product GUI allows a specially crafted attack to bypass the authentication requirements of the system, resulting in the ability to remotely change the superuser password. This can be used by an attacker to gain administrative control or to deny service. IBM X-Force ID: 150296.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-1822

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

FlashSystem 900
Vulnerable Versions:
Unknown

Timeline

Official Publish: October 18th, 2018
Last Modified: February 13th, 2025
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/A:H/AC:L/AV:N/C:H/I:H/PR:N/S:U/UI:N/E:U/RC:C/RL:O

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.