CVE-2018-1859: Medium severity api connect cli plugins vulnerability
Published Jan 4, 2019
·Updated
IBM API Connect 5.0.0.0 through 5.0.8.4 could allow a user authenticated as an administrator with limited rights to escalate their privileges. IBM X-Force ID: 151258.
Affected Software
1 affected component
IBM API Connect>=5.0.0.0<=5.0.8.4
Remediation
Patch Available
Event History
Jan 4, 2019
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1859?
CVE-2018-1859 has a medium severity level, indicating that it poses a moderate risk to affected systems.
2
How do I fix CVE-2018-1859?
To fix CVE-2018-1859, upgrade IBM API Connect to a version that is not vulnerable, preferably 5.0.9.0 or later.
3
Who is affected by CVE-2018-1859?
CVE-2018-1859 affects users of IBM API Connect versions from 5.0.0.0 to 5.0.8.4.
4
What type of vulnerability is CVE-2018-1859?
CVE-2018-1859 is a privilege escalation vulnerability that allows an authenticated user with limited rights to gain higher privileges.
5
Can CVE-2018-1859 be exploited remotely?
CVE-2018-1859 requires authenticated access, so it cannot be exploited remotely without valid administrator credentials.