CVE-2021-29772: Code Injection
Published Aug 25, 2021
·Updated
IBM API Connect 5.0.0.0 through 5.0.8.11 could allow a user to potentially inject code due to unsanitized user input. IBM X-Force ID: 202774.
Other sources
IBM API Connect could allow a user to potentially inject code due to unsanitized user input.
Affected Software
2 affected components
IBM API Connect>=5.0.0.0<=5.0.8.11
IBM API Connect<=IBM API Connect V5.0.0.0-5.0.8.11
Remediation
Patch Available
Event History
Aug 25, 2021
CVE Published
via IBM·12:00 AM
Aug 26, 2021
CVE Published
via MITRE·07:25 PM
Data Sourced
via MITRE·07:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-29772?
CVE-2021-29772 is a vulnerability in IBM API Connect that could allow a user to potentially inject code due to unsanitized user input.
2
What is the severity of CVE-2021-29772?
The severity of CVE-2021-29772 is critical with a CVSS score of 9.8.
3
How does CVE-2021-29772 affect IBM API Connect?
CVE-2021-29772 affects IBM API Connect versions 5.0.0.0 through 5.0.8.11.
4
How can a user potentially exploit CVE-2021-29772?
A user can potentially exploit CVE-2021-29772 by injecting malicious code through unsanitized user input in IBM API Connect.
5
Is there a fix available for CVE-2021-29772?
Yes, IBM has provided a fix for CVE-2021-29772. Please refer to the official IBM support page for more details.