CVE-2021-20440: Medium severity api connect cli plugins vulnerability
IBM API Connect 10.0.0.0, and 2018.4.1.0 through 2018.4.1.13 does not restrict member registration to the intended recepient. An attacker who is a valid user in the user registry used by API Manager can use a stolen invitation link and register themselves as a member of an API provider organization. IBM X-Force ID: 196536.
Other sources
IBM API Manager does not restrict member registration to the intended recepient. An attacker who is a valid user in the user registry used by API Manager can use a stolen invitation link and register themselves as a member of an API provider organization.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-20440.
What is the severity of CVE-2021-20440?
The severity of CVE-2021-20440 is medium with a CVSS score of 6.4.
What is the affected software?
The affected software includes IBM API Connect versions 10.0.0.0 and 2018.4.1.0 through 2018.4.1.13.
How does the vulnerability in IBM API Manager allow unauthorized registration?
The vulnerability allows an attacker who is a valid user in the user registry used by API Manager to register themselves as a member of an API provider organization using a stolen invitation link.
How can I fix CVE-2021-20440?
To fix the vulnerability, apply the necessary patches provided by IBM.