Back to Database
Status published
Critical
CVE-2018-19646
The Python CGI scripts in PWS in Imperva SecureSphere 13.0.10,...
Vulnerability Description
The Python CGI scripts in PWS in Imperva SecureSphere 13.0.10, 13.1.10, and 13.2.10 allow remote attackers to execute arbitrary OS commands because command-line arguments are mishandled.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-19646
Credits & Attribution
No credits recorded in the NVD database.
References
More from imperva
View All →CVE-2021-45468
Imperva Web Application Firewall (WAF) before 2021-12-23 allows remote unauthenticated...
Critical
9.8
CVE-2018-16660
A command injection vulnerability in PWS in Imperva SecureSphere 13.0.0.10...
High
8.8
CVE-2013-4095
plain/actionsets.html in the SecureSphere Operations Manager (SOM) Management Server in...
Medium
6.5
CVE-2013-4094
The Key Management feature in the SecureSphere Operations Manager (SOM)...
Medium
6.5
CVE-2013-4093
The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere...
Medium
5
Affected Vendor
imperva
View all reports →Affected Software
securesphere
Vulnerable Versions:
13.0.10, 13.1.10, 13.2.10
Timeline
Official Publish:
November 28th, 2018
Last Modified:
September 17th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.