PT-2019-17086 · Ibm · Ibm Api Connect
Publicado
2019-12-16
·
Atualizado
2020-08-24
·
CVE-2019-4444
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM API Connect versions 2018.1 through 2018.4.1.7
Description
The issue concerns the user registration page of the Developer Portal, which does not disable password autocomplete. This allows an attacker with access to the browser instance and local system credentials to potentially steal the credentials used for registration.
Recommendations
For IBM API Connect versions 2018.1 through 2018.4.1.7, consider disabling the password autocomplete feature on the Developer Portal's user registration page as a temporary workaround until a patch is available. Restrict access to the registration page to minimize the risk of exploitation.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Api Connect