CVE-2018-2009
published 2019-03-11CVE-2018-2009: IBM API Connect v2018.1 and 2018.4.1 is affected by an information disclosure vulnerability in the consumer API. Any registered user can obtain a list of all…
PriorityP434medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
1.65%
73.7th percentile
IBM API Connect v2018.1 and 2018.4.1 is affected by an information disclosure vulnerability in the consumer API. Any registered user can obtain a list of all other users in all other orgs, including email id/names, etc. IBM X-Force ID: 155148.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | api_connect | — | — |
| ibm | api_connect | — | — |
| ibm | api_connect | 2018.1.0 – 2018.4.1.0 | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
ghsa5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache ODE Path Traversal vulnerability
ghsa·2022-05-14·CVSS 5.0
CVE-2018-1316 [MEDIUM] CWE-22 Apache ODE Path Traversal vulnerability
Apache ODE Path Traversal vulnerability
The ODE process deployment web service was sensible to deployment messages with forged names. Using a path for the name was allowing directory traversal, resulting in the potential writing of files under unwanted locations, the overwriting of existing files or their deletion. This issue was addressed in Apache ODE 1.3.3 which was released in 2009, however the incorrect name CVE-2008-2370 was used on the advisory by mistake.
GHSA
GHSA-c963-547x-7462: IBM API Connect v2018
ghsa_unreviewed·2022-05-13
CVE-2018-2009 [MEDIUM] CWE-200 GHSA-c963-547x-7462: IBM API Connect v2018
IBM API Connect v2018.1 and 2018.4.1 is affected by an information disclosure vulnerability in the consumer API. Any registered user can obtain a list of all other users in all other orgs, including email id/names, etc. IBM X-Force ID: 155148.
No detection rules found.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/107396https://exchange.xforce.ibmcloud.com/vulnerabilities/155148https://www.ibm.com/support/docview.wss?uid=ibm10794327http://www.securityfocus.com/bid/107396https://exchange.xforce.ibmcloud.com/vulnerabilities/155148https://www.ibm.com/support/docview.wss?uid=ibm10794327
2019-03-11
Published