CVE-2018-1932: Infoleak
Published Jan 2, 2019
·Updated
IBM API Connect 5.0.0.0 through 5.0.8.4 is affected by a vulnerability in the role-based access control in the management server that could allow an authenticated user to obtain highly sensitive information. IBM X-Force ID: 153175.
Affected Software
1 affected component
IBM API Connect>=5.0.0.0<=5.0.8.4
Remediation
Patch Available
Event History
Jan 8, 2019
CVE Published
04:29 PM
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1932?
CVE-2018-1932 has a moderate severity level due to its impact on role-based access control allowing sensitive information exposure.
2
How do I fix CVE-2018-1932?
To fix CVE-2018-1932, upgrade IBM API Connect to a version beyond 5.0.8.4.
3
Who is affected by CVE-2018-1932?
CVE-2018-1932 affects users of IBM API Connect versions from 5.0.0.0 to 5.0.8.4.
4
What type of information can be exposed by CVE-2018-1932?
CVE-2018-1932 can potentially expose highly sensitive information to authenticated users.
5
Is authentication sufficient in preventing CVE-2018-1932?
No, authentication alone is not sufficient to prevent CVE-2018-1932 as it involves role-based access control vulnerabilities.