CVE-2017-1328: Medium severity api connect cli plugins vulnerability
IBM API Connect 5.0.0.0 - 5.0.6.0 could allow a remote attacker to bypass security restrictions of the api, caused by improper handling of security policy. By crafting a suitable request, an attacker could exploit this vulnerability to bypass security and use the vulnerable API. IBM X-Force ID: 126230.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1328?
CVE-2017-1328 is considered a medium severity vulnerability that allows remote attackers to bypass security restrictions.
Which versions of IBM API Connect are affected by CVE-2017-1328?
IBM API Connect versions 5.0.0.0 through 5.0.6.0 are affected by CVE-2017-1328.
How do I fix CVE-2017-1328?
To fix CVE-2017-1328, upgrade to the latest version of IBM API Connect that addresses the vulnerability.
What kind of attack can exploit CVE-2017-1328?
CVE-2017-1328 can be exploited by crafting specific requests to bypass security policies of the affected API.
What impact does CVE-2017-1328 have on API security?
CVE-2017-1328 potentially allows unauthorized access and manipulation of APIs, severely compromising API security.