First published: Fri Feb 01 2019(Updated: )
API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak. Authorization tokens in some URLs can result in the tokens being written to log files. IBM X-Force ID: 155626.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM API Connect | >=2018.1.0<=2018.4.1.1 | |
>=2018.1.0<=2018.4.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4008 is considered a medium severity vulnerability due to the potential for access token leaks.
CVE-2019-4008 allows authorization tokens to be inadvertently logged, creating a risk of exposure.
To remediate CVE-2019-4008, upgrade API Connect to a version later than 2018.4.1.1.
CVE-2019-4008 affects IBM API Connect versions from 2018.1.0 up to and including 2018.4.1.1.
If you suspect your installation is vulnerable to CVE-2019-4008, immediately review your logging practices and consider upgrading to a secure version.