PT-2019-16865 · Ibm · Ibm Api Connect

Published

2019-03-22

·

Updated

2023-02-03

·

CVE-2019-4052

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM API Connect versions 2018.1 through 2018.4.1.2
Description The issue allows unauthenticated users to discover login ids of registered users by leveraging IBM API Connect apis.
Recommendations For IBM API Connect versions 2018.1 through 2018.4.1.2, consider restricting access to the affected apis to prevent unauthenticated users from discovering login ids of registered users.

Fix

Related Identifiers

CVE-2019-4052

Affected Products

Ibm Api Connect