First published: Mon May 11 2020(Updated: )
IBM API Connect's management server has an unsecured api which can be exploited by an unauthenticated attacker to obtain sensitive information.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM API Connect | >=2018.4.1.0<=2018.4.1.10 | |
<=V2018.4.1.0-2018.4.1.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-4346 is medium with a CVSS score of 5.3.
An unauthenticated attacker can exploit CVE-2020-4346 by accessing the unsecured API of IBM API Connect's management server to obtain sensitive information.
IBM API Connect versions V2018.4.1.0 through 2018.4.1.10 are affected by CVE-2020-4346.
Yes, IBM has released a patch for CVE-2020-4346. You can find it at the following URL: http://www.ibm.com/support/fixcentral/swg/quickorder?parent=ibm%7EWebSphere&product=ibm/WebSphere/IBM+API+Connect&release=2018.4.1.10&platform=All&function=all&source=fc
You can find more information about CVE-2020-4346 at the following URLs: - https://exchange.xforce.ibmcloud.com/vulnerabilities/178322 - https://www.ibm.com/support/pages/node/6208328