First published: Thu Jul 26 2018(Updated: )
IBM API Connect 5.0.0.0-5.0.8.3 Developer Portal does not enforce Two Factor Authentication (TFA) while resetting a user password but enforces it for all other login scenarios. IBM X-Force ID: 144483.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM API Connect | >=5.0.0.0<=5.0.8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1638 has a medium severity rating due to the lack of Two Factor Authentication during password resets.
To mitigate CVE-2018-1638, ensure that Regular Two Factor Authentication is enforced for password resets within IBM API Connect.
CVE-2018-1638 affects IBM API Connect versions 5.0.0.0 to 5.0.8.3.
The primary risk of CVE-2018-1638 is that unauthorized users could exploit the password reset functionality without proper authentication, leading to account takeover.
Until a patch is applied for CVE-2018-1638, administrators should manually enforce enhanced password security measures and closely monitor account activity.