Security readout for executives and security teams
This issue affects specific IBM Security Access Manager Appliance 9.0.x releases that used weaker cryptography than expected. The business risk is exposure of highly sensitive information if an attacker can defeat the protection. The public record rates it medium severity, not a broad system takeover. Exposure is limited to organizations running IBM Security Access Manager Appliance versions 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, or 9.0.5.0. The main concern is sensitive data protected by affected cryptographic behavior. Handle as a moderate-priority confidentiality risk in identity or access infrastructure. It does not indicate active exploitation from the provided sources, but affected systems protect sensitive information and should be verified promptly. Mitigation focus: Inventory IBM Security Access Manager Appliance versions in production and support environments.; Prioritize remediation for any appliance at versions 9.0.1.0 through 9.0.5.0.; Use IBM’s advisory as the authority for official fixes or configuration guidance..
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2018-1814 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 5.9 (3.0)
- Known Exploited
- No
- Published
Vector: CVSS:3.0/A:N/AC:H/AV:N/C:H/I:N/PR:N/S:U/UI:N/E:U/RC:C/RL:O
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.0/A:N/AC:H/AV:N/C:H/I:N/PR:N/S:U/UI:N/E:U/RC:C/RL:O2.23.6Primary CVE scoreVulnerability scoring details
Base CVSS 3.0 score
5.9MediumVector: CVSS:3.0/A:N/AC:H/AV:N/C:H/I:N/PR:N/S:U/UI:N/E:U/RC:C/RL:O
Source materials
- CVE List V5 sourceCVE List V5
- ibm-sam-cve20181814-info-disc(150018)CVE reference · vdb-entry, x_refsource_XF
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
