PT-2018-15063 · Ibm · Ibm Api Connect

Published

2018-12-20

·

Updated

2019-10-09

·

CVE-2018-1973

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM API Connect versions 5.0.0.0 through 5.0.8.4
Description The issue allows a user with limited 'API Administrator' level access to escalate their privileges to full 'Administrator' level access. This is achieved through the members functionality.
Recommendations For versions 5.0.0.0 through 5.0.8.4, consider restricting access to the members functionality to prevent privilege escalation until a fix is available.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1973

Affected Products

Ibm Api Connect