CVE-2018-1789: SSRF
Published Sep 4, 2018
·Updated
IBM API Connect v2018.1.0 through v2018.3.4 could allow an attacker to send a specially crafted request to conduct a server side request forgery attack. IBM X-Force ID: 148939.
Affected Software
1 affected component
IBM API Connect>=2018.1.0<=2018.3.4
Remediation
Patch Available
Event History
Sep 7, 2018
CVE Published
03:29 PM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1789?
CVE-2018-1789 is considered a medium severity vulnerability that allows for server side request forgery attacks.
2
How do I fix CVE-2018-1789?
To mitigate CVE-2018-1789, upgrade IBM API Connect to a version later than v2018.3.4.
3
What products are affected by CVE-2018-1789?
CVE-2018-1789 affects IBM API Connect versions from 2018.1.0 to 2018.3.4.
4
Can CVE-2018-1789 lead to data breaches?
Yes, if exploited, CVE-2018-1789 could allow attackers to access sensitive information via server side request forgery.
5
What type of attack does CVE-2018-1789 involve?
CVE-2018-1789 involves a server side request forgery attack, which manipulates server requests.