← Vulnerability feed

Vulnerability record · CVE-2018-1756 · published 7 September 2018

CVE-2018-1756: Ibm security identity governance and intelligence sql injection vulnerability

Ibm · Security Identity Governance And Intelligence

IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, information in the back-end database. IBM X-Force ID: 148599.

7.5 CVSS 3.0 High EPSS 11% · top 4.4% CWE-89 · SQL injection
7.5CVSS 3.0 base score, v2 5.0
11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, information in the back-end database. IBM X-Force ID: 148599.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-1756 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-4958Ibm security identity governance and intelligence missing authentication for critical function vulnerabilityIBM Security Identity Governance and Intelligence 5.2.6 does not perform any authentication for functionality that requires a provable user identity …EPSS 1.7%9.8CVE-2018-1944Ibm security identity governance and intelligence hard-coded credentials vulnerabilityIBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance contains hard-coded credentials, such as a password or crypto…EPSS 0.84%8.8CVE-2017-1407Ibm security identity governance and intelligence command injection vulnerabilityIBM Security Identity Manager Virtual Appliance 6.0 and 7.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. …EPSS 3.4%8.6CVE-2017-1483Ibm security identity governance and intelligence missing authentication for critical function vulnerabilityIBM Security Identity Manager Adapters 6.0 and 7.0 does not perform an authentication check for a critical resource or functionality allowing anonymo…EPSS 1.5%8.2CVE-2020-4795Ibm security identity governance and intelligence vulnerabilityIBM Security Identity Governance and Intelligence 5.2.6 could disclose sensitive information to an unauthorized user using a specially crafted HTTP r…EPSS 1.7%8.1CVE-2017-1396Ibm security identity governance and intelligence vulnerabilityIBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 specifies permissions for a security-critical resource in a way that allows th…EPSS 0.81%7.5CVE-2020-4232Ibm security identity governance and intelligence improper restriction of authentication attempts vulnerabilityIBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to enumerate usernames to find valid login credentials which could be…EPSS 1.1%7.5CVE-2020-4245Ibm security identity governance and intelligence weak password requirements vulnerabilityIBM Security Identity Governance and Intelligence 5.2.6 does not require that users should have strong passwords by default, which makes it easier fo…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2018-1756), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.