CVE-2018-1638: High severity IBM API Connect vulnerability
IBM API Connect 5.0.0.0-5.0.8.3 Developer Portal does not enforce Two Factor Authentication (TFA) while resetting a user password but enforces it for all other login scenarios. IBM X-Force ID: 144483.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1638?
CVE-2018-1638 has a medium severity rating due to the lack of Two Factor Authentication during password resets.
How do I fix CVE-2018-1638?
To mitigate CVE-2018-1638, ensure that Regular Two Factor Authentication is enforced for password resets within IBM API Connect.
What systems are affected by CVE-2018-1638?
CVE-2018-1638 affects IBM API Connect versions 5.0.0.0 to 5.0.8.3.
What potential risks are associated with CVE-2018-1638?
The primary risk of CVE-2018-1638 is that unauthorized users could exploit the password reset functionality without proper authentication, leading to account takeover.
Is there a workaround for CVE-2018-1638?
Until a patch is applied for CVE-2018-1638, administrators should manually enforce enhanced password security measures and closely monitor account activity.