CVE-2020-4337: Medium severity api connect cli plugins vulnerability
IBM API Connect 2018.4.1.0 through 2018.4.1.12 could allow an attacker to launch phishing attacks by tricking the server to generate user registration emails that contain malicious URLs. IBM X-Force ID: 177933.
Other sources
IBM API Connect could allow an attacker to launch phishing attacks by tricking the server to generate user registration emails that contain malicious URLs.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-4337.
What is the severity of CVE-2020-4337?
The severity of CVE-2020-4337 is medium (severity value of 6.5).
How can an attacker exploit CVE-2020-4337?
An attacker can exploit CVE-2020-4337 by tricking the server to generate user registration emails that contain malicious URLs, which can be used for phishing attacks.
Is there a patch available for CVE-2020-4337?
Yes, there is a patch available for CVE-2020-4337. For IBM API Connect 2018.4.1.0 through 2018.4.1.12, the patch can be downloaded from IBM Fix Central. For IBM API Connect V10.0.0, the patch can be downloaded from IBM Support.
Where can I find more information about CVE-2020-4337?
You can find more information about CVE-2020-4337 on the IBM X-Force Exchange website and IBM Support.