CVE-2020-4903: Medium severity api connect cli plugins vulnerability
IBM API Connect could allow an attacker who has intercepted a registration invitation link to impersonate the registered user or obtain sensitive information.
Other sources
IBM API Connect V10 and V2018 could allow an attacker who has intercepted a registration invitation link to impersonate the registered user or obtain sensitive information. IBM X-Force ID: 191105.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4903?
CVE-2020-4903 is classified as a medium severity vulnerability, as it allows impersonation and exposure of sensitive information.
How do I fix CVE-2020-4903?
To fix CVE-2020-4903, update to IBM API Connect version 10.0.1.1 or V2018.4.1.14 and apply all security patches.
What are the affected versions for CVE-2020-4903?
CVE-2020-4903 affects IBM API Connect versions up to 10.0.1.1 and V2018.4.1.0 to 2018.4.1.13.
What type of attack is possible through CVE-2020-4903?
CVE-2020-4903 allows an attacker to intercept a registration invitation link, leading to user impersonation and potential data theft.
Who is impacted by CVE-2020-4903?
Organizations using IBM API Connect versions that are susceptible to CVE-2020-4903 are at risk from this vulnerability.