CVE-2018-1774: High severity IBM API Connect vulnerability
IBM API Connect 5.0.0.0, 5.0.8.4, 2018.1 and 2018.3.6 is vulnerable to CSV injection via the developer portal and analytics that could contain malicious commands that would be executed once opened by an administrator. IBM X-Force ID: 148692.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1774?
CVE-2018-1774 has been classified as a high severity vulnerability due to its potential for exploitation via CSV injection.
How do I fix CVE-2018-1774?
To remediate CVE-2018-1774, it is essential to upgrade IBM API Connect to a version that addresses this vulnerability.
Who is affected by CVE-2018-1774?
CVE-2018-1774 affects users of IBM API Connect versions 5.0.0.0, 5.0.8.4, 2018.1, and 2018.3.6.
What are the implications of CVE-2018-1774?
The implications of CVE-2018-1774 include the risk of executing malicious commands on systems when opening contaminated CSV files.
Is there a workaround for CVE-2018-1774?
Currently, there are no documented workarounds for CVE-2018-1774, and users should prioritize upgrading their systems.