CVE-2017-1386: Medium severity api connect cli plugins vulnerability
IBM API Connect 5.0.0.0 could allow a user to bypass policy restrictions and create non-compliant passwords which could be intercepted and decrypted using man in the middle techniques. IBM X-Force ID: 127160.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1386?
CVE-2017-1386 is categorized as a medium to high severity vulnerability due to the potential for password policy bypass and interception.
How do I fix CVE-2017-1386?
To fix CVE-2017-1386, update IBM API Connect and IBM API Management to a version that includes the patch addressing this vulnerability.
What versions are affected by CVE-2017-1386?
CVE-2017-1386 affects IBM API Connect versions 5.0.0.0 to 5.0.7.0 and IBM API Management versions 4.0.0.0 to 4.0.4.5.
What can happen if CVE-2017-1386 is exploited?
If CVE-2017-1386 is exploited, attackers could bypass policy restrictions and create passwords that may be intercepted and decrypted.
Is there a workaround for CVE-2017-1386?
There is no official workaround for CVE-2017-1386; the recommended action is to apply the necessary software updates.