CVE-2018-1976: Infoleak
Published Jan 29, 2019
·Updated
IBM API Connect 5.0.0.0 through 5.0.8.4 is impacted by sensitive information disclosure via a REST API that could allow a user with administrative privileges to obtain highly sensitive information. IBM X-Force ID: 154031.
Affected Software
1 affected component
IBM API Connect>=5.0.0.0<=5.0.8.4
Remediation
Patch Available
Event History
Jan 29, 2019
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1976?
The severity of CVE-2018-1976 is considered to be high due to potential sensitive information disclosure.
2
How do I fix CVE-2018-1976?
To address CVE-2018-1976, it is recommended to upgrade IBM API Connect to a version higher than 5.0.8.4.
3
Who is affected by CVE-2018-1976?
The vulnerability CVE-2018-1976 affects IBM API Connect versions 5.0.0.0 through 5.0.8.4.
4
What type of information is exposed in CVE-2018-1976?
CVE-2018-1976 can lead to the exposure of highly sensitive information via a REST API.
5
What privileges are required to exploit CVE-2018-1976?
Exploitation of CVE-2018-1976 requires administrative privileges on the affected system.