CVE-2018-1469: Critical severity IBM API Connect vulnerability
Published Apr 4, 2018
·Updated
IBM API Connect Developer Portal 5.0.0.0 through 5.0.8.2 could allow an unauthenticated attacker to execute system commands using specially crafted HTTP requests. IBM X-Force ID: 140605.
Affected Software
3 affected components
IBM API Connect>=5.0.0.0<=5.0.6.6
IBM API Connect>=5.0.7.0<=5.0.7.2
IBM API Connect>=5.0.8.0<=5.0.8.2
Remediation
Patch Available
Event History
Apr 4, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1469?
CVE-2018-1469 is considered a critical vulnerability due to its potential for unauthenticated command execution.
2
How do I fix CVE-2018-1469?
To mitigate CVE-2018-1469, upgrade IBM API Connect to version 5.0.8.3 or later.
3
What types of attacks does CVE-2018-1469 allow?
CVE-2018-1469 allows unauthenticated attackers to execute arbitrary system commands.
4
Which versions of IBM API Connect are affected by CVE-2018-1469?
CVE-2018-1469 affects IBM API Connect versions 5.0.0.0 to 5.0.8.2.
5
Is CVE-2018-1469 still a threat if I'm using a patched version?
If you are using a patched version (5.0.8.3 or later), CVE-2018-1469 should no longer pose a threat.