PT-2019-17086 · Ibm · Ibm Api Connect

Published

2019-12-16

·

Updated

2020-08-24

·

CVE-2019-4444

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM API Connect versions 2018.1 through 2018.4.1.7
Description The issue concerns the user registration page of the Developer Portal, which does not disable password autocomplete. This allows an attacker with access to the browser instance and local system credentials to potentially steal the credentials used for registration.
Recommendations For IBM API Connect versions 2018.1 through 2018.4.1.7, consider disabling the password autocomplete feature on the Developer Portal's user registration page as a temporary workaround until a patch is available. Restrict access to the registration page to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-4444

Affected Products

Ibm Api Connect