PT-2019-17086 · Ibm · Ibm Api Connect

Publicado

2019-12-16

·

Atualizado

2020-08-24

·

CVE-2019-4444

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM API Connect versions 2018.1 through 2018.4.1.7
Description The issue concerns the user registration page of the Developer Portal, which does not disable password autocomplete. This allows an attacker with access to the browser instance and local system credentials to potentially steal the credentials used for registration.
Recommendations For IBM API Connect versions 2018.1 through 2018.4.1.7, consider disabling the password autocomplete feature on the Developer Portal's user registration page as a temporary workaround until a patch is available. Restrict access to the registration page to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-4444

Produtos afetados

Ibm Api Connect