CVE-2019-4008: Critical severity api connect cli plugins vulnerability
Published Feb 1, 2019
·Updated
API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak. Authorization tokens in some URLs can result in the tokens being written to log files. IBM X-Force ID: 155626.
Affected Software
1 affected component
IBM API Connect>=2018.1.0<=2018.4.1.1
Remediation
Patch Available
Event History
Feb 7, 2019
CVE Published
03:29 PM
Data Sourced
via NVD·03:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-4008?
CVE-2019-4008 is considered a medium severity vulnerability due to the potential for access token leaks.
2
How does CVE-2019-4008 impact API Connect?
CVE-2019-4008 allows authorization tokens to be inadvertently logged, creating a risk of exposure.
3
How do I fix CVE-2019-4008?
To remediate CVE-2019-4008, upgrade API Connect to a version later than 2018.4.1.1.
4
Which versions of API Connect are affected by CVE-2019-4008?
CVE-2019-4008 affects IBM API Connect versions from 2018.1.0 up to and including 2018.4.1.1.
5
What should I do if I suspect my API Connect installation is vulnerable to CVE-2019-4008?
If you suspect your installation is vulnerable to CVE-2019-4008, immediately review your logging practices and consider upgrading to a secure version.