First published: Mon Dec 16 2019(Updated: )
IBM API Connect 2018.1 through 2018.4.1.7 Developer Portal's user registration page does not disable password autocomplete. An attacker with access to the browser instance and local system credentials can steal the credentials used for registration. IBM X-Force ID: 163453.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM API Connect | >=2018.1.0<=2018.4.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2019-4444.
CVE-2019-4444 has a severity rating of medium.
The vulnerability allows an attacker with local system credentials to steal the credentials used for registration by exploiting the lack of password autocomplete disablement.
IBM API Connect versions 2018.1 through 2018.4.1.7 are affected by this vulnerability.
The CWE ID for this vulnerability is CWE-200.