CVE-2019-4051: Infoleak
Some URIs in IBM API Connect 2018.1 and 2018.4.1.3 disclose system specification information like the machine id, system uuid, filesystem paths, network interface names along with their mac addresses. An attacker can use this information in targeted attacks. IBM X-Force ID: 156542.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-4051?
CVE-2019-4051 is considered a moderate severity vulnerability due to the potential exposure of sensitive system information.
How do I fix CVE-2019-4051?
To mitigate CVE-2019-4051, it is recommended to upgrade to a patched version of IBM API Connect after reviewing IBM's official guidance.
What kind of information is disclosed by CVE-2019-4051?
CVE-2019-4051 exposes system specification information including machine id, system UUID, filesystem paths, and network interface names with their MAC addresses.
What versions of IBM API Connect are affected by CVE-2019-4051?
CVE-2019-4051 affects IBM API Connect versions from 2018.1.0 to 2018.4.1.3 inclusive.
Can CVE-2019-4051 be exploited for targeted attacks?
Yes, an attacker can exploit CVE-2019-4051 by using the disclosed information for targeted attacks on the system.