VYPR

API Connect

by IBM

CVEs (82)

  • CVE-2019-4402HigAug 20, 2019
    risk 0.49cvss 7.5epss 0.02

    IBM API Connect 2018.1 through 2018.4.1.6 developer portal could allow an unauthorized user to cause a denial of service via an unprotected API. IBM X-Force ID: 162263.

  • CVE-2019-4256HigMay 29, 2019
    risk 0.49cvss 7.5epss 0.01

    IBM API Connect 5.0.0.0 through 5.0.8.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 159944.

  • CVE-2019-4052HigMar 22, 2019
    risk 0.49cvss 7.5epss 0.02

    IBM API Connect 2018.1 and 2018.4.1.2 apis can be leveraged by unauthenticated users to discover login ids of registered users. IBM X-Force ID: 156544.

  • CVE-2018-1779HigNov 20, 2018
    risk 0.49cvss 7.5epss 0.02

    IBM API Connect 2018.1 through 2018.3.7 could allow an unauthenticated attacker to cause a denial of service due to not setting limits on JSON payload size. IBM X-Force ID: 148802.

  • CVE-2017-1379HigJun 15, 2017
    risk 0.49cvss 7.5epss 0.02

    IBM API Connect 5.0.0.0 could allow a remote attacker to obtain sensitive information, caused by improper handling of requests to the Developer Portal. IBM X-Force ID: 127002.

  • CVE-2016-3012HigDec 1, 2016
    risk 0.49cvss 7.5epss 0.02

    IBM API Connect (aka APIConnect) before 5.0.3.0 with NPM before 2.2.8 includes certain internal server credentials in the software package, which might allow remote attackers to bypass intended access restrictions by leveraging knowledge of these credentials.

  • CVE-2017-1161HigApr 17, 2017
    risk 0.48cvss 7.3epss 0.01

    IBM API Connect 5.0.6.0 could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of URLs for the Developer Portal. By crafting a malicious URL, an attacker could exploit this vulnerability to execute arbitrary commands on the…

  • CVE-2020-4638HigSep 3, 2020
    risk 0.47cvss 7.2epss 0.02

    IBM API Connect's API Manager 2018.4.1.0 through 2018.4.1.12 is vulnerable to privilege escalation. An invitee to an API Provider organization can escalate privileges by manipulating the invitation link. IBM X-Force ID: 185508.

  • CVE-2018-1973HigDec 20, 2018
    risk 0.47cvss 7.2epss 0.02

    IBM API Connect 5.0.0.0 through 5.0.8.4 allows a user with limited 'API Administrator level access to give themselves full 'Administrator' level access through the members functionality. IBM X-Force ID: 153914.

  • CVE-2018-1784HigDec 20, 2018
    risk 0.46cvss 7.1epss 0.02

    IBM API Connect 5.0.0.0 and 5.0.8.4 is affected by a NoSQL Injection in MongoDB connector for the LoopBack framework. IBM X-Force ID: 148807.

  • CVE-2020-4903MedMar 8, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM API Connect V10 and V2018 could allow an attacker who has intercepted a registration invitation link to impersonate the registered user or obtain sensitive information. IBM X-Force ID: 191105.

  • CVE-2020-4828MedFeb 4, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to web cache poisoning, caused by improper input validation by modifying HTTP request headers. IBM X-Force ID: 189842.

  • CVE-2020-4337MedSep 3, 2020
    risk 0.42cvss 6.5epss 0.01

    IBM API Connect 2018.4.1.0 through 2018.4.1.12 could allow an attacker to launch phishing attacks by tricking the server to generate user registration emails that contain malicious URLs. IBM X-Force ID: 177933.

  • CVE-2018-2015MedMay 2, 2019
    risk 0.42cvss 6.4epss 0.02

    IBM API Connect 2018.1 and 2018.4.1.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch…

  • CVE-2018-2009MedMar 11, 2019
    risk 0.42cvss 6.5epss 0.02

    IBM API Connect v2018.1 and 2018.4.1 is affected by an information disclosure vulnerability in the consumer API. Any registered user can obtain a list of all other users in all other orgs, including email id/names, etc. IBM X-Force ID: 155148.

  • CVE-2018-1389MedApr 30, 2018
    risk 0.42cvss 6.5epss 0.02

    IBM API Connect 5.0.0.0 through 5.0.8.2 is impacted by generated LoopBack APIs for a Model using the BelongsTo/HasMany relationship allowing unauthorized modification of information. IBM X-Force ID: 138213.

  • CVE-2017-1556MedSep 13, 2017
    risk 0.42cvss 6.5epss 0.01

    IBM API Connect 5.0.7.0 through 5.0.7.2 is vulnerable to a regular expression attack that could allow an authenticated attacker to use a regex and cause the system to slow or hang. IBM X-Force ID: 131546.

  • CVE-2023-47722MedDec 9, 2023
    risk 0.40cvss 6.2epss 0.00

    IBM API Connect V10.0.5.3 and V10.0.6.0 stores user credentials in browser cache which can be read by a local user. IBM X-Force ID: 271912.

  • CVE-2017-1551MedSep 25, 2017
    risk 0.40cvss 6.1epss 0.01

    IBM API Connect 5.0.0.0 through 5.0.7.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch…

  • CVE-2018-1546MedJul 6, 2018
    risk 0.39cvss 5.9epss 0.02

    IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle…

Page 2 of 5