CVE-2018-1973: Critical severity api connect cli plugins vulnerability
Published Dec 20, 2018
·Updated
IBM API Connect 5.0.0.0 through 5.0.8.4 allows a user with limited 'API Administrator level access to give themselves full 'Administrator' level access through the members functionality. IBM X-Force ID: 153914.
Affected Software
1 affected component
IBM API Connect>=5.0.0.0<=5.0.8.4
Remediation
Patch Available
Event History
Dec 20, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1973?
The severity of CVE-2018-1973 is classified as high due to the potential for an API administrator to escalate privileges.
2
How do I fix CVE-2018-1973?
To fix CVE-2018-1973, update IBM API Connect to a version later than 5.0.8.4.
3
What versions of IBM API Connect are affected by CVE-2018-1973?
IBM API Connect versions from 5.0.0.0 to 5.0.8.4 are affected by CVE-2018-1973.
4
What kind of access can be gained through CVE-2018-1973?
CVE-2018-1973 allows a user with limited API Administrator access to elevate themselves to full Administrator access.
5
Who reported CVE-2018-1973?
CVE-2018-1973 was reported by IBM X-Force as vulnerability ID 153914.