PT-2019-17086 · Ibm · Ibm Api Connect
Published
2019-12-16
·
Updated
2020-08-24
·
CVE-2019-4444
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM API Connect versions 2018.1 through 2018.4.1.7
Description
The issue concerns the user registration page of the Developer Portal, which does not disable password autocomplete. This allows an attacker with access to the browser instance and local system credentials to potentially steal the credentials used for registration.
Recommendations
For IBM API Connect versions 2018.1 through 2018.4.1.7, consider disabling the password autocomplete feature on the Developer Portal's user registration page as a temporary workaround until a patch is available. Restrict access to the registration page to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Api Connect