PT-2021-12190 · Ibm · Ibm Api Connect

Published

2021-02-04

·

Updated

2021-02-05

·

CVE-2020-4828

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions IBM API Connect versions 10.0.0.0 through 10.0.1.0 IBM API Connect versions 2018.4.1.0 through 2018.4.1.13
Description The issue is caused by improper input validation, allowing web cache poisoning by modifying HTTP request headers.
Recommendations For versions 10.0.0.0 through 10.0.1.0, update to a version outside of this range to resolve the issue. For versions 2018.4.1.0 through 2018.4.1.13, update to a version outside of this range to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-4828

Affected Products

Ibm Api Connect