cbcvebase.

Ibm Api Connect vulnerabilities

81 known vulnerabilities affecting ibm/api_connect.

Total CVEs
81
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL14HIGH22MEDIUM44LOW1

Vulnerabilities

Page 1 of 5
CVE-2018-1932P1MEDIUMCVSS 4.9ExploitedRansomware≥ 5.0.0.0, ≤ 5.0.8.4v5.0.0.0+1 more2019-01-08
CVE-2018-1932 [MEDIUM] CWE-200 CVE-2018-1932: IBM API Connect 5.0.0.0 through 5.0.8.4 is affected by a vulnerability in the role-based access cont IBM API Connect 5.0.0.0 through 5.0.8.4 is affected by a vulnerability in the role-based access control in the management server that could allow an authenticated user to obtain highly sensitive information. IBM X-Force ID: 153175.
nvd
CVE-2025-13915P2CRITICALCVSS 9.8≥ 10.0.8.0, ≤ 10.0.8.5v10.0.11.02025-12-26
CVE-2025-13915 [CRITICAL] CWE-305 CVE-2025-13915: IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass aut IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.
nvd
CVE-2019-4202P2CRITICALCVSS 10.0≥ 5.0.0.0, ≤ 5.0.8.6v5.0.0.0+1 more2019-04-15
CVE-2019-4202 [CRITICAL] CWE-78 CVE-2019-4202: IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal is vulnerable to command injection. An attacker IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal is vulnerable to command injection. An attacker with a specially crafted request can run arbitrary code on the server and gain complete access to the system. IBM X-Force ID: 159123.
nvd
CVE-2026-9074P2CRITICALCVSS 9.8≥ 10.0.8.0, < 10.0.8.10≥ 12.1.0.0, < 12.1.1.0+2 more2026-07-08
CVE-2026-9074 [CRITICAL] CWE-89 CVE-2026-9074: IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.
nvd
CVE-2026-3144P3CRITICALCVSS 9.8≥ 12.1.0.0, < 12.1.1.0≥ 12.1.0.0, < 12.1.0.32026-07-08
CVE-2026-3144 [CRITICAL] CWE-1392 CVE-2026-3144: IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
nvd
CVE-2018-1469P3CRITICALCVSS 9.8≥ 5.0.0.0, ≤ 5.0.6.6≥ 5.0.7.0, ≤ 5.0.7.2+20 more2018-04-04
CVE-2018-1469 [CRITICAL] CVE-2018-1469: IBM API Connect Developer Portal 5.0.0.0 through 5.0.8.2 could allow an unauthenticated attacker to IBM API Connect Developer Portal 5.0.0.0 through 5.0.8.2 could allow an unauthenticated attacker to execute system commands using specially crafted HTTP requests. IBM X-Force ID: 140605.
nvd
CVE-2018-1789P3CRITICALCVSS 9.9≥ 2018.1.0, ≤ 2018.3.4v2018.2.1+15 more2018-09-07
CVE-2018-1789 [CRITICAL] CWE-918 CVE-2018-1789: IBM API Connect v2018.1.0 through v2018.3.4 could allow an attacker to send a specially crafted requ IBM API Connect v2018.1.0 through v2018.3.4 could allow an attacker to send a specially crafted request to conduct a server side request forgery attack. IBM X-Force ID: 148939.
nvd
CVE-2019-4203P3CRITICALCVSS 9.8≥ 5.0.0.0, ≤ 5.0.8.6v5.0.0.0+1 more2019-04-15
CVE-2019-4203 [CRITICAL] CWE-918 CVE-2019-4203: IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal can be exploited by app developers to download IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal can be exploited by app developers to download arbitrary files from the host OS and potentially carry out SSRF attacks. IBM X-Force ID: 159124.
nvd
CVE-2018-1778P3HIGHCVSS 8.1≥ 5.0.8.0, ≤ 5.0.8.4≥ 2018.1.0, ≤ 2018.4.1.0+4 more2018-12-20
CVE-2018-1778 [HIGH] CWE-287 CVE-2018-1778: IBM LoopBack (IBM API Connect 2018.1, 2018.4.1, 5.0.8.0, and 5.0.8.4) could allow an attacker to byp IBM LoopBack (IBM API Connect 2018.1, 2018.4.1, 5.0.8.0, and 5.0.8.4) could allow an attacker to bypass authentication if the AccessToken Model is exposed over a REST API, it is then possible for anyone to create an AccessToken for any User provided they know the userId and can hence get access to the other user’s data / access to their privileges
nvd
CVE-2019-4155P3CRITICALCVSS 9.8≥ 2018.1.0, ≤ 2018.4.1.3v2018.1+1 more2019-04-08
CVE-2019-4155 [CRITICAL] CVE-2019-4155: IBM API Connect's Developer Portal 2018.1 and 2018.4.1.3 is impacted by a privilege escalation vulne IBM API Connect's Developer Portal 2018.1 and 2018.4.1.3 is impacted by a privilege escalation vulnerability when integrated with an OpenID Connect (OIDC) user registry. IBM X-Force ID: 158544.
nvd
CVE-2018-1784P3CRITICALCVSS 9.8≥ 5.0.0.0, ≤ 5.0.8.4v5.0.0.0+1 more2018-12-20
CVE-2018-1784 [CRITICAL] CVE-2018-1784: IBM API Connect 5.0.0.0 and 5.0.8.4 is affected by a NoSQL Injection in MongoDB connector for the Lo IBM API Connect 5.0.0.0 and 5.0.8.4 is affected by a NoSQL Injection in MongoDB connector for the LoopBack framework. IBM X-Force ID: 148807.
nvd
CVE-2018-1712P3CRITICALCVSS 9.9≥ 5.0.0.0, ≤ 5.0.8.3v5.0.1.0+20 more2018-08-16
CVE-2018-1712 [CRITICAL] CWE-352 CVE-2018-1712: IBM API Connect's Developer Portal 5.0.0.0 through 5.0.8.3 is vulnerable to Server Side Request Forg IBM API Connect's Developer Portal 5.0.0.0 through 5.0.8.3 is vulnerable to Server Side Request Forgery. An attacker, using specially crafted input parameters can trick the server into making potentially malicious calls within the trusted network. IBM X-Force ID: 146370.
nvd
CVE-2019-4008P3CRITICALCVSS 9.8≥ 2018.1.0, ≤ 2018.4.1.1v2018.1+1 more2019-02-07
CVE-2019-4008 [CRITICAL] CWE-532 CVE-2019-4008: API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak. Authorization tokens in som API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak. Authorization tokens in some URLs can result in the tokens being written to log files. IBM X-Force ID: 155626.
nvd
CVE-2021-29715P3CRITICALCVSS 9.1≥ 5.0.0.0, ≤ 5.0.8.11v5.0.0.0+1 more2021-08-26
CVE-2021-29715 [CRITICAL] CVE-2021-29715: IBM API Connect 5.0.0.0 through 5.0.8.11 could alllow a remote user to obtain sensitive information IBM API Connect 5.0.0.0 through 5.0.8.11 could alllow a remote user to obtain sensitive information or conduct denial of serivce attacks due to open ports. IBM X-Force ID: 201018.
nvd
CVE-2017-1322P3HIGHCVSS 8.2v5.0.0.0v5.0.0.1+9 more2017-06-27
CVE-2017-1322 [HIGH] CWE-611 CVE-2017-1322: IBM API Connect 5.0.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processi IBM API Connect 5.0.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 125918.
nvd
CVE-2023-28522P3HIGHCVSS 8.8≥ 10.0.0.0, < 10.0.1.11≥ 10.0.2.0, < 10.0.5.2+2 more2023-05-12
CVE-2023-28522 [HIGH] CWE-732 CVE-2023-28522: IBM API Connect V10 could allow an authenticated user to perform actions that they should not have a IBM API Connect V10 could allow an authenticated user to perform actions that they should not have access to. IBM X-Force ID: 250585.
nvd
CVE-2019-4460P3HIGHCVSS 7.5≥ 5.0.0.0, ≤ 5.0.8.6v5.0.0.0+1 more2019-08-20
CVE-2019-4460 [HIGH] CWE-22 CVE-2019-4460: IBM API Connect 5.0.0.0 through 5.0.8.6 developer portal could allow a remote attacker to traverse d IBM API Connect 5.0.0.0 through 5.0.8.6 developer portal could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 163681.
nvd
CVE-2017-1161P3HIGHCVSS 7.3v5.0.6.02017-04-17
CVE-2017-1161 [HIGH] CWE-20 CVE-2017-1161: IBM API Connect 5.0.6.0 could allow a remote attacker to execute arbitrary commands on the system, c IBM API Connect 5.0.6.0 could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of URLs for the Developer Portal. By crafting a malicious URL, an attacker could exploit this vulnerability to execute arbitrary commands on the system with the privileges of the www-data user. IBM X-Force ID: 122956.
nvd
CVE-2021-29772P3CRITICALCVSS 9.8≥ 5.0.0.0, ≤ 5.0.8.11v5.0.0.0+1 more2021-08-26
CVE-2021-29772 [CRITICAL] CWE-94 CVE-2021-29772: IBM API Connect 5.0.0.0 through 5.0.8.11 could allow a user to potentially inject code due to unsani IBM API Connect 5.0.0.0 through 5.0.8.11 could allow a user to potentially inject code due to unsanitized user input. IBM X-Force ID: 202774.
nvd
CVE-2016-3012P3HIGHCVSS 7.5≤ 5.0.2.02016-12-01
CVE-2016-3012 [HIGH] CWE-200 CVE-2016-3012: IBM API Connect (aka APIConnect) before 5.0.3.0 with NPM before 2.2.8 includes certain internal serv IBM API Connect (aka APIConnect) before 5.0.3.0 with NPM before 2.2.8 includes certain internal server credentials in the software package, which might allow remote attackers to bypass intended access restrictions by leveraging knowledge of these credentials.
nvd
Ibm Api Connect vulnerabilities | cvebase