CVE-2018-1784: SQL Injection
Published Dec 20, 2018
·Updated
IBM API Connect 5.0.0.0 and 5.0.8.4 is affected by a NoSQL Injection in MongoDB connector for the LoopBack framework. IBM X-Force ID: 148807.
Affected Software
1 affected component
IBM API Connect>=5.0.0.0<=5.0.8.4
Remediation
Patch Available
Event History
Dec 20, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1784?
CVE-2018-1784 is classified as a high severity vulnerability due to its potential impact on data integrity through NoSQL Injection.
2
How do I fix CVE-2018-1784?
To fix CVE-2018-1784, upgrade to a version of IBM API Connect that exceeds 5.0.8.4.
3
What versions are vulnerable to CVE-2018-1784?
IBM API Connect versions 5.0.0.0 to 5.0.8.4 are vulnerable to CVE-2018-1784.
4
What is the specific vulnerability type in CVE-2018-1784?
CVE-2018-1784 is a NoSQL Injection vulnerability affecting the MongoDB connector in the LoopBack framework.
5
Is there a workaround for CVE-2018-1784?
There are no specific workarounds documented for CVE-2018-1784, so upgrading is recommended as the primary mitigation strategy.