CVE-2016-3012Sensitive Information Exposure in IBM API Connect

Severity
7.5HIGHNVD
EPSS
0.2%
top 63.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 1
Latest updateMay 17

Description

IBM API Connect (aka APIConnect) before 5.0.3.0 with NPM before 2.2.8 includes certain internal server credentials in the software package, which might allow remote attackers to bypass intended access restrictions by leveraging knowledge of these credentials.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDibm/api_connect5.0.2.0

🔴Vulnerability Details

2
GHSA
GHSA-pgrv-2wj5-4hc4: IBM API Connect (aka APIConnect) before 52022-05-17
CVEList
CVE-2016-3012: IBM API Connect (aka APIConnect) before 52016-12-01
CVE-2016-3012 — Sensitive Information Exposure in IBM | cvebase