CVE-2018-1858: CSRF
IBM API Connect 5.0.0.0 through 5.0.8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 151256.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-1858?
CVE-2018-1858 is a vulnerability in IBM API Connect 5.0.0.0 through 5.0.8.6 that allows for cross-site request forgery, enabling an attacker to execute unauthorized actions through a trusted user.
What is the severity of CVE-2018-1858?
The severity of CVE-2018-1858 is high with a severity value of 8.8.
How does CVE-2018-1858 affect IBM API Connect?
CVE-2018-1858 affects IBM API Connect versions 5.0.0.0 through 5.0.8.6.
How can an attacker exploit CVE-2018-1858?
An attacker can exploit CVE-2018-1858 by tricking a trusted user into performing malicious actions.
Are there any references for CVE-2018-1858?
Yes, you can find references for CVE-2018-1858 at the following URLs: [Link 1](http://www.ibm.com/support/docview.wss?uid=ibm10794169), [Link 2](http://www.securityfocus.com/bid/108898), [Link 3](http://www.securityfocus.com/bid/109111).