First published: Tue Jan 29 2019(Updated: )
IBM API Connect 5.0.0.0 through 5.0.8.4 is impacted by sensitive information disclosure via a REST API that could allow a user with administrative privileges to obtain highly sensitive information. IBM X-Force ID: 154031.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
API Connect CLI Plugins | >=5.0.0.0<=5.0.8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1976 is considered to be high due to potential sensitive information disclosure.
To address CVE-2018-1976, it is recommended to upgrade IBM API Connect to a version higher than 5.0.8.4.
The vulnerability CVE-2018-1976 affects IBM API Connect versions 5.0.0.0 through 5.0.8.4.
CVE-2018-1976 can lead to the exposure of highly sensitive information via a REST API.
Exploitation of CVE-2018-1976 requires administrative privileges on the affected system.