First published: Wed Mar 20 2019(Updated: )
IBM API Connect 2018.1 and 2018.4.1.2 apis can be leveraged by unauthenticated users to discover login ids of registered users. IBM X-Force ID: 156544.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
API Connect CLI Plugins | >=2018.1.0<=2018.4.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4052 is classified as a medium severity vulnerability due to its potential for user enumeration by unauthenticated users.
To fix CVE-2019-4052, update IBM API Connect to a version higher than 2018.4.1.2.
CVE-2019-4052 affects IBM API Connect versions 2018.1 and 2018.4.1.2.
Yes, CVE-2019-4052 can be exploited remotely by unauthenticated users.
CVE-2019-4052 allows attackers to discover login IDs of registered users, thereby compromising user confidentiality.