CVE-2018-1774Improper Neutralization of Formula Elements in a CSV File in IBM API Connect

Severity
7.8HIGHNVD
CNA8.9
EPSS
0.1%
top 70.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 9
Latest updateMay 13

Description

IBM API Connect 5.0.0.0, 5.0.8.4, 2018.1 and 2018.3.6 is vulnerable to CSV injection via the developer portal and analytics that could contain malicious commands that would be executed once opened by an administrator. IBM X-Force ID: 148692.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDibm/api_connect5.0.0.05.0.8.4+1
CVEListV5ibm/api_connect4 versions+3

🔴Vulnerability Details

2
GHSA
GHSA-4w78-h86p-3c63: IBM API Connect 52022-05-13
CVEList
CVE-2018-1774: IBM API Connect 52018-11-09
CVE-2018-1774 — IBM API Connect vulnerability | cvebase