CVE-2017-1555Improper Input Validation in IBM API Connect

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 55.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 25
Latest updateMay 17

Description

IBM API Connect 5.0.0.0 through 5.0.7.2 could allow an authenticated user to generate an API token when not subscribed to the application plan. IBM X-Force ID: 131545.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

CVEListV5ibm/api_connect14 versions+13
NVDibm/api_connect15 versions+14

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6qpg-q62m-qghr: IBM API Connect 52022-05-17
CVEList
CVE-2017-1555: IBM API Connect 52017-09-25
CVE-2017-1555 — Improper Input Validation in IBM | cvebase