First published: Wed May 22 2019(Updated: )
IBM API Connect 5.0.0.0, and 5.0.8.6 could could return sensitive information that could provide critical information as to the underlying software stack in CMC UI headers. IBM X-Force ID: 154284.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM API Connect | >=5.0.0.0<=5.0.8.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1991 has been classified with a medium severity level due to the risk of exposing sensitive information.
To fix CVE-2018-1991, upgrade IBM API Connect to a version later than 5.0.8.6.
CVE-2018-1991 allows attackers to gain access to sensitive information that can reveal details about the underlying software stack.
CVE-2018-1991 affects IBM API Connect versions from 5.0.0.0 to 5.0.8.6.
There are no specific workarounds mentioned for CVE-2018-1991; upgrading is the recommended solution.