CVE-2019-4203: SSRF
Published Apr 15, 2019
·Updated
IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal can be exploited by app developers to download arbitrary files from the host OS and potentially carry out SSRF attacks. IBM X-Force ID: 159124.
Affected Software
1 affected component
IBM API Connect>=5.0.0.0<=5.0.8.6
Event History
Apr 15, 2019
CVE Published
via MITRE·02:55 PM
Data Sourced
via MITRE·02:55 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-4203?
CVE-2019-4203 is classified as a high-severity vulnerability due to its potential for arbitrary file download and SSRF attacks.
2
How do I fix CVE-2019-4203?
To mitigate CVE-2019-4203, upgrade IBM API Connect to version 5.0.8.7 or later, which addresses this vulnerability.
3
What types of attacks can CVE-2019-4203 facilitate?
CVE-2019-4203 can facilitate arbitrary file downloads and Server-Side Request Forgery (SSRF) attacks.
4
Which software versions are affected by CVE-2019-4203?
IBM API Connect versions 5.0.0.0 to 5.0.8.6 are affected by CVE-2019-4203.
5
Who can exploit CVE-2019-4203?
Application developers with access to the IBM API Connect Developer Portal can exploit CVE-2019-4203.