First published: Thu Sep 03 2020(Updated: )
IBM API Connect's API Manager 2018.4.1.0 through 2018.4.1.12 is vulnerable to privilege escalation. An invitee to an API Provider organization can escalate privileges by manipulating the invitation link. IBM X-Force ID: 185508.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM API Connect | >=2018.4.1.0<=2018.4.1.12 | |
<=V2018.4.1.0-2018.4.1.12 | ||
<=V10.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-4638.
The severity level of CVE-2020-4638 is high (7.2).
IBM API Connect versions V2018.4.1.0 through V2018.4.1.12 and V10.0.0 are affected by this vulnerability.
By manipulating the invitation link, an invitee can escalate privileges in IBM API Connect's API Manager 2018.4.1.0 through 2018.4.1.12.
The vulnerability can be fixed by applying the available patches provided by IBM. Please refer to the following links for patch information: [IBM API Connect 2018.4.1.0-2018.4.1.12](http://www.ibm.com/support/fixcentral/swg/quickorder?parent=ibm%7EWebSphere&product=ibm/WebSphere/IBM+API+Connect&release=2018.4.1.12&platform=All&function=all&source=fc) and [IBM API Connect V10.0.0](https://www.ibm.com/support/pages/node/6339249).