CVE-2019-4155: Critical severity api connect cli plugins vulnerability
Published Apr 8, 2019
·Updated
IBM API Connect's Developer Portal 2018.1 and 2018.4.1.3 is impacted by a privilege escalation vulnerability when integrated with an OpenID Connect (OIDC) user registry. IBM X-Force ID: 158544.
Affected Software
1 affected component
IBM API Connect>=2018.1.0<=2018.4.1.3
Event History
Apr 8, 2019
CVE Published
via MITRE·02:50 PM
Data Sourced
via MITRE·02:50 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:29 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-4155?
CVE-2019-4155 is a privilege escalation vulnerability which can significantly impact the security of IBM API Connect's Developer Portal.
2
How do I fix CVE-2019-4155?
To fix CVE-2019-4155, update IBM API Connect to a version higher than 2018.4.1.3.
3
What products are affected by CVE-2019-4155?
CVE-2019-4155 affects IBM API Connect versions 2018.1 and 2018.4.1.3 when integrated with an OpenID Connect user registry.
4
What type of vulnerability is CVE-2019-4155?
CVE-2019-4155 is classified as a privilege escalation vulnerability.
5
Can CVE-2019-4155 be exploited remotely?
Yes, CVE-2019-4155 can potentially be exploited remotely due to its integration with OpenID Connect.