CVE-2018-1389: Medium severity api connect cli plugins vulnerability
Published Apr 30, 2018
·Updated
IBM API Connect 5.0.0.0 through 5.0.8.2 is impacted by generated LoopBack APIs for a Model using the BelongsTo/HasMany relationship allowing unauthorized modification of information. IBM X-Force ID: 138213.
Affected Software
1 affected component
IBM API Connect>=5.0.0.0<=5.0.8.2
Event History
Apr 30, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1389?
CVE-2018-1389 has a medium severity rating due to the potential for unauthorized modifications.
2
How do I fix CVE-2018-1389?
To fix CVE-2018-1389, upgrade IBM API Connect to the latest version that addresses this vulnerability.
3
What versions of IBM API Connect are affected by CVE-2018-1389?
IBM API Connect versions 5.0.0.0 through 5.0.8.2 are affected by CVE-2018-1389.
4
What type of attack does CVE-2018-1389 involve?
CVE-2018-1389 involves unauthorized modification of information through generated LoopBack APIs.
5
Is user authentication sufficient to prevent CVE-2018-1389?
No, user authentication alone is not sufficient as this vulnerability allows unauthorized access under certain conditions.