CVE-2017-1556: Input Validation
IBM API Connect 5.0.7.0 through 5.0.7.2 is vulnerable to a regular expression attack that could allow an authenticated attacker to use a regex and cause the system to slow or hang. IBM X-Force ID: 131546.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1556?
CVE-2017-1556 is classified as a moderate severity vulnerability due to the potential performance impact on the affected systems.
How do I fix CVE-2017-1556?
To mitigate CVE-2017-1556, upgrading IBM API Connect to a version later than 5.0.7.2 is recommended.
What versions of IBM API Connect are affected by CVE-2017-1556?
CVE-2017-1556 affects IBM API Connect versions 5.0.7.0, 5.0.7.1, and 5.0.7.2.
Who can exploit CVE-2017-1556?
CVE-2017-1556 can be exploited by authenticated attackers who can craft and send malicious regular expressions.
What is the impact of CVE-2017-1556?
The impact of CVE-2017-1556 includes potential degradation of system performance, which may lead to slowing down or hanging of the application.