Ibm Api Connect vulnerabilities
81 known vulnerabilities affecting ibm/api_connect.
Total CVEs
81
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL14HIGH22MEDIUM44LOW1
Vulnerabilities
Page 1 of 5
CVE-2018-1932P1MEDIUMCVSS 4.9ExploitedRansomware≥ 5.0.0.0, ≤ 5.0.8.4v5.0.0.0+1 more2019-01-08
CVE-2018-1932 [MEDIUM] CWE-200 CVE-2018-1932: IBM API Connect 5.0.0.0 through 5.0.8.4 is affected by a vulnerability in the role-based access cont
IBM API Connect 5.0.0.0 through 5.0.8.4 is affected by a vulnerability in the role-based access control in the management server that could allow an authenticated user to obtain highly sensitive information. IBM X-Force ID: 153175.
nvd
CVE-2025-13915P2CRITICALCVSS 9.8≥ 10.0.8.0, ≤ 10.0.8.5v10.0.11.02025-12-26
CVE-2025-13915 [CRITICAL] CWE-305 CVE-2025-13915: IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass aut
IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.
nvd
CVE-2019-4202P2CRITICALCVSS 10.0≥ 5.0.0.0, ≤ 5.0.8.6v5.0.0.0+1 more2019-04-15
CVE-2019-4202 [CRITICAL] CWE-78 CVE-2019-4202: IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal is vulnerable to command injection. An attacker
IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal is vulnerable to command injection. An attacker with a specially crafted request can run arbitrary code on the server and gain complete access to the system. IBM X-Force ID: 159123.
nvd
CVE-2026-9074P2CRITICALCVSS 9.8≥ 10.0.8.0, < 10.0.8.10≥ 12.1.0.0, < 12.1.1.0+2 more2026-07-08
CVE-2026-9074 [CRITICAL] CWE-89 CVE-2026-9074: IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated
IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.
nvd
CVE-2026-3144P3CRITICALCVSS 9.8≥ 12.1.0.0, < 12.1.1.0≥ 12.1.0.0, < 12.1.0.32026-07-08
CVE-2026-3144 [CRITICAL] CWE-1392 CVE-2026-3144: IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
nvd
CVE-2018-1469P3CRITICALCVSS 9.8≥ 5.0.0.0, ≤ 5.0.6.6≥ 5.0.7.0, ≤ 5.0.7.2+20 more2018-04-04
CVE-2018-1469 [CRITICAL] CVE-2018-1469: IBM API Connect Developer Portal 5.0.0.0 through 5.0.8.2 could allow an unauthenticated attacker to
IBM API Connect Developer Portal 5.0.0.0 through 5.0.8.2 could allow an unauthenticated attacker to execute system commands using specially crafted HTTP requests. IBM X-Force ID: 140605.
nvd
CVE-2018-1789P3CRITICALCVSS 9.9≥ 2018.1.0, ≤ 2018.3.4v2018.2.1+15 more2018-09-07
CVE-2018-1789 [CRITICAL] CWE-918 CVE-2018-1789: IBM API Connect v2018.1.0 through v2018.3.4 could allow an attacker to send a specially crafted requ
IBM API Connect v2018.1.0 through v2018.3.4 could allow an attacker to send a specially crafted request to conduct a server side request forgery attack. IBM X-Force ID: 148939.
nvd
CVE-2019-4203P3CRITICALCVSS 9.8≥ 5.0.0.0, ≤ 5.0.8.6v5.0.0.0+1 more2019-04-15
CVE-2019-4203 [CRITICAL] CWE-918 CVE-2019-4203: IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal can be exploited by app developers to download
IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal can be exploited by app developers to download arbitrary files from the host OS and potentially carry out SSRF attacks. IBM X-Force ID: 159124.
nvd
CVE-2018-1778P3HIGHCVSS 8.1≥ 5.0.8.0, ≤ 5.0.8.4≥ 2018.1.0, ≤ 2018.4.1.0+4 more2018-12-20
CVE-2018-1778 [HIGH] CWE-287 CVE-2018-1778: IBM LoopBack (IBM API Connect 2018.1, 2018.4.1, 5.0.8.0, and 5.0.8.4) could allow an attacker to byp
IBM LoopBack (IBM API Connect 2018.1, 2018.4.1, 5.0.8.0, and 5.0.8.4) could allow an attacker to bypass authentication if the AccessToken Model is exposed over a REST API, it is then possible for anyone to create an AccessToken for any User provided they know the userId and can hence get access to the other user’s data / access to their privileges
nvd
CVE-2019-4155P3CRITICALCVSS 9.8≥ 2018.1.0, ≤ 2018.4.1.3v2018.1+1 more2019-04-08
CVE-2019-4155 [CRITICAL] CVE-2019-4155: IBM API Connect's Developer Portal 2018.1 and 2018.4.1.3 is impacted by a privilege escalation vulne
IBM API Connect's Developer Portal 2018.1 and 2018.4.1.3 is impacted by a privilege escalation vulnerability when integrated with an OpenID Connect (OIDC) user registry. IBM X-Force ID: 158544.
nvd
CVE-2018-1784P3CRITICALCVSS 9.8≥ 5.0.0.0, ≤ 5.0.8.4v5.0.0.0+1 more2018-12-20
CVE-2018-1784 [CRITICAL] CVE-2018-1784: IBM API Connect 5.0.0.0 and 5.0.8.4 is affected by a NoSQL Injection in MongoDB connector for the Lo
IBM API Connect 5.0.0.0 and 5.0.8.4 is affected by a NoSQL Injection in MongoDB connector for the LoopBack framework. IBM X-Force ID: 148807.
nvd
CVE-2018-1712P3CRITICALCVSS 9.9≥ 5.0.0.0, ≤ 5.0.8.3v5.0.1.0+20 more2018-08-16
CVE-2018-1712 [CRITICAL] CWE-352 CVE-2018-1712: IBM API Connect's Developer Portal 5.0.0.0 through 5.0.8.3 is vulnerable to Server Side Request Forg
IBM API Connect's Developer Portal 5.0.0.0 through 5.0.8.3 is vulnerable to Server Side Request Forgery. An attacker, using specially crafted input parameters can trick the server into making potentially malicious calls within the trusted network. IBM X-Force ID: 146370.
nvd
CVE-2019-4008P3CRITICALCVSS 9.8≥ 2018.1.0, ≤ 2018.4.1.1v2018.1+1 more2019-02-07
CVE-2019-4008 [CRITICAL] CWE-532 CVE-2019-4008: API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak. Authorization tokens in som
API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak. Authorization tokens in some URLs can result in the tokens being written to log files. IBM X-Force ID: 155626.
nvd
CVE-2021-29715P3CRITICALCVSS 9.1≥ 5.0.0.0, ≤ 5.0.8.11v5.0.0.0+1 more2021-08-26
CVE-2021-29715 [CRITICAL] CVE-2021-29715: IBM API Connect 5.0.0.0 through 5.0.8.11 could alllow a remote user to obtain sensitive information
IBM API Connect 5.0.0.0 through 5.0.8.11 could alllow a remote user to obtain sensitive information or conduct denial of serivce attacks due to open ports. IBM X-Force ID: 201018.
nvd
CVE-2017-1322P3HIGHCVSS 8.2v5.0.0.0v5.0.0.1+9 more2017-06-27
CVE-2017-1322 [HIGH] CWE-611 CVE-2017-1322: IBM API Connect 5.0.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processi
IBM API Connect 5.0.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 125918.
nvd
CVE-2023-28522P3HIGHCVSS 8.8≥ 10.0.0.0, < 10.0.1.11≥ 10.0.2.0, < 10.0.5.2+2 more2023-05-12
CVE-2023-28522 [HIGH] CWE-732 CVE-2023-28522: IBM API Connect V10 could allow an authenticated user to perform actions that they should not have a
IBM API Connect V10 could allow an authenticated user to perform actions that they should not have access to. IBM X-Force ID: 250585.
nvd
CVE-2019-4460P3HIGHCVSS 7.5≥ 5.0.0.0, ≤ 5.0.8.6v5.0.0.0+1 more2019-08-20
CVE-2019-4460 [HIGH] CWE-22 CVE-2019-4460: IBM API Connect 5.0.0.0 through 5.0.8.6 developer portal could allow a remote attacker to traverse d
IBM API Connect 5.0.0.0 through 5.0.8.6 developer portal could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 163681.
nvd
CVE-2017-1161P3HIGHCVSS 7.3v5.0.6.02017-04-17
CVE-2017-1161 [HIGH] CWE-20 CVE-2017-1161: IBM API Connect 5.0.6.0 could allow a remote attacker to execute arbitrary commands on the system, c
IBM API Connect 5.0.6.0 could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of URLs for the Developer Portal. By crafting a malicious URL, an attacker could exploit this vulnerability to execute arbitrary commands on the system with the privileges of the www-data user. IBM X-Force ID: 122956.
nvd
CVE-2021-29772P3CRITICALCVSS 9.8≥ 5.0.0.0, ≤ 5.0.8.11v5.0.0.0+1 more2021-08-26
CVE-2021-29772 [CRITICAL] CWE-94 CVE-2021-29772: IBM API Connect 5.0.0.0 through 5.0.8.11 could allow a user to potentially inject code due to unsani
IBM API Connect 5.0.0.0 through 5.0.8.11 could allow a user to potentially inject code due to unsanitized user input. IBM X-Force ID: 202774.
nvd
CVE-2016-3012P3HIGHCVSS 7.5≤ 5.0.2.02016-12-01
CVE-2016-3012 [HIGH] CWE-200 CVE-2016-3012: IBM API Connect (aka APIConnect) before 5.0.3.0 with NPM before 2.2.8 includes certain internal serv
IBM API Connect (aka APIConnect) before 5.0.3.0 with NPM before 2.2.8 includes certain internal server credentials in the software package, which might allow remote attackers to bypass intended access restrictions by leveraging knowledge of these credentials.
nvd
1 / 5Next →