CVE-2020-4828: Input Validation
IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to web cache poisoning, caused by improper input validation by modifying HTTP request headers. IBM X-Force ID: 189842.
Other sources
IBM API Connect is vulnerable to web cache poisoning, caused by improper input validation by modifying HTTP request headers.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2020-4828.
What is the severity of CVE-2020-4828?
The severity of CVE-2020-4828 is medium with a CVSS score of 6.5.
What is the affected software?
The affected software includes IBM API Connect versions 10.0.0.0 through 10.0.1.0, and versions 2018.4.1.0 through 2018.4.1.13.
How does CVE-2020-4828 affect IBM API Connect?
CVE-2020-4828 allows web cache poisoning in IBM API Connect due to improper input validation by modifying HTTP request headers.
Is there a reference link for more information on CVE-2020-4828?
Yes, you can find more information on CVE-2020-4828 at the IBM X-Force ID: 189842 and the IBM support pages.