First published: Fri Jan 04 2019(Updated: )
IBM API Connect 5.0.0.0 through 5.0.8.4 could allow a user authenticated as an administrator with limited rights to escalate their privileges. IBM X-Force ID: 151258.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
API Connect CLI Plugins | >=5.0.0.0<=5.0.8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1859 has a medium severity level, indicating that it poses a moderate risk to affected systems.
To fix CVE-2018-1859, upgrade IBM API Connect to a version that is not vulnerable, preferably 5.0.9.0 or later.
CVE-2018-1859 affects users of IBM API Connect versions from 5.0.0.0 to 5.0.8.4.
CVE-2018-1859 is a privilege escalation vulnerability that allows an authenticated user with limited rights to gain higher privileges.
CVE-2018-1859 requires authenticated access, so it cannot be exploited remotely without valid administrator credentials.