PT-2018-13532 · Ibm · Ibm Api Connect

Published

2018-07-31

·

Updated

2019-10-09

·

CVE-2018-1638

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM API Connect versions 5.0.0.0 through 5.0.8.3
Description The issue concerns the enforcement of Two Factor Authentication (TFA) during password reset. Normally, TFA is required for login scenarios, but it is not enforced when resetting a user's password.
Recommendations For versions 5.0.0.0 through 5.0.8.3, consider implementing additional authentication measures to enforce TFA during password reset until a fix is available.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1638

Affected Products

Ibm Api Connect