First published: Thu Aug 16 2018(Updated: )
IBM API Connect's Developer Portal 5.0.0.0 through 5.0.8.3 is vulnerable to Server Side Request Forgery. An attacker, using specially crafted input parameters can trick the server into making potentially malicious calls within the trusted network. IBM X-Force ID: 146370.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM API Connect | >=5.0.0.0<=5.0.8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1712 is rated as a medium severity vulnerability due to the risk of Server Side Request Forgery.
To mitigate CVE-2018-1712, it is recommended to apply the latest security patches provided by IBM for the affected versions.
The affected versions of IBM API Connect range from 5.0.0.0 to 5.0.8.3.
CVE-2018-1712 is classified as a Server Side Request Forgery (SSRF) vulnerability.
Yes, an attacker can exploit CVE-2018-1712 remotely by sending specially crafted input parameters to the server.