CVE-2018-2011: Infoleak
Published Jun 25, 2019
·Updated
IBM API Connect 2018.1 through 2018.4.1.5 could allow an attacker to obtain sensitive information from a specially crafted HTTP request that could aid an attacker in further attacks against the system. IBM X-Force ID: 155150.
Affected Software
1 affected component
IBM API Connect>=2018.1.0<=2018.4.1.5
Remediation
Patch Available
Event History
Jun 25, 2019
CVE Published
via MITRE·03:45 PM
Data Sourced
via MITRE·03:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-2011?
CVE-2018-2011 is considered a moderate severity vulnerability due to its potential to expose sensitive information.
2
How do I fix CVE-2018-2011?
To address CVE-2018-2011, update IBM API Connect to version 2018.4.1.6 or later.
3
What systems are affected by CVE-2018-2011?
CVE-2018-2011 affects IBM API Connect versions from 2018.1 through 2018.4.1.5.
4
What type of attack is possible with CVE-2018-2011?
CVE-2018-2011 could allow an attacker to exploit specially crafted HTTP requests to gain sensitive information.
5
Who reported CVE-2018-2011?
CVE-2018-2011 was reported by IBM's X-Force team and is cataloged under IBM X-Force ID: 155150.