First published: Sun Nov 04 2018(Updated: )
IBM API Connect 5.0.0.0, 5.0.8.4, 2018.1 and 2018.3.6 is vulnerable to CSV injection via the developer portal and analytics that could contain malicious commands that would be executed once opened by an administrator. IBM X-Force ID: 148692.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM API Connect | >=5.0.0.0<=5.0.8.4 | |
IBM API Connect | >=2018.1.0<=2018.3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1774 has been classified as a high severity vulnerability due to its potential for exploitation via CSV injection.
To remediate CVE-2018-1774, it is essential to upgrade IBM API Connect to a version that addresses this vulnerability.
CVE-2018-1774 affects users of IBM API Connect versions 5.0.0.0, 5.0.8.4, 2018.1, and 2018.3.6.
The implications of CVE-2018-1774 include the risk of executing malicious commands on systems when opening contaminated CSV files.
Currently, there are no documented workarounds for CVE-2018-1774, and users should prioritize upgrading their systems.