First published: Tue Sep 04 2018(Updated: )
IBM API Connect v2018.1.0 through v2018.3.4 could allow an attacker to send a specially crafted request to conduct a server side request forgery attack. IBM X-Force ID: 148939.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
API Connect CLI Plugins | >=2018.1.0<=2018.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1789 is considered a medium severity vulnerability that allows for server side request forgery attacks.
To mitigate CVE-2018-1789, upgrade IBM API Connect to a version later than v2018.3.4.
CVE-2018-1789 affects IBM API Connect versions from 2018.1.0 to 2018.3.4.
Yes, if exploited, CVE-2018-1789 could allow attackers to access sensitive information via server side request forgery.
CVE-2018-1789 involves a server side request forgery attack, which manipulates server requests.