cbcvebase.

Ibm Api Connect vulnerabilities

81 known vulnerabilities affecting ibm/api_connect.

Total CVEs
81
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL14HIGH22MEDIUM44LOW1

Vulnerabilities

Page 2 of 5
CVE-2020-4899P3CRITICALCVSS 9.1≥ 5.0.0.0, ≤ 5.0.8.10v5.0.0.0+1 more2021-01-05
CVE-2020-4899 [CRITICAL] CWE-319 CVE-2020-4899: IBM API Connect 5.0.0.0 through 5.0.8.10 could potentially leak sensitive information or allow for d IBM API Connect 5.0.0.0 through 5.0.8.10 could potentially leak sensitive information or allow for data corruption due to plain text transmission of sensitive information across the network. IBM X-Force ID: 190990.
nvd
CVE-2018-1638P3HIGHCVSS 8.1≥ 5.0.0.0, ≤ 5.0.8.3v5.0.0.0-5.0.8.32018-07-31
CVE-2018-1638 [HIGH] CWE-287 CVE-2018-1638: IBM API Connect 5.0.0.0-5.0.8.3 Developer Portal does not enforce Two Factor Authentication (TFA) wh IBM API Connect 5.0.0.0-5.0.8.3 Developer Portal does not enforce Two Factor Authentication (TFA) while resetting a user password but enforces it for all other login scenarios. IBM X-Force ID: 144483.
nvd
CVE-2022-34350P3HIGHCVSS 7.5≥ 10.0.0.0, ≤ 10.0.5.0≥ 10.0.1.0, ≤ 10.0.1.7+4 more2023-02-08
CVE-2022-34350 [HIGH] CWE-20 CVE-2022-34350: IBM API Connect 10.0.0.0 through 10.0.5.0, 10.0.1.0 through 10.0.1.7, and 2018.4.1.0 through 2018.4. IBM API Connect 10.0.0.0 through 10.0.5.0, 10.0.1.0 through 10.0.1.7, and 2018.4.1.0 through 2018.4.1.20 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary
nvd
CVE-2017-1379P3HIGHCVSS 7.5v5.0.0.0v5.0.0.1+10 more2017-06-15
CVE-2017-1379 [HIGH] CWE-200 CVE-2017-1379: IBM API Connect 5.0.0.0 could allow a remote attacker to obtain sensitive information, caused by imp IBM API Connect 5.0.0.0 could allow a remote attacker to obtain sensitive information, caused by improper handling of requests to the Developer Portal. IBM X-Force ID: 127002.
nvd
CVE-2019-4052P3HIGHCVSS 7.5≥ 2018.1.0, ≤ 2018.4.1.2v2018.1+1 more2019-03-22
CVE-2019-4052 [HIGH] CVE-2019-4052: IBM API Connect 2018.1 and 2018.4.1.2 apis can be leveraged by unauthenticated users to discover log IBM API Connect 2018.1 and 2018.4.1.2 apis can be leveraged by unauthenticated users to discover login ids of registered users. IBM X-Force ID: 156544.
nvd
CVE-2018-1973P3HIGHCVSS 7.2≥ 5.0.0.0, ≤ 5.0.8.4v5.0.0.0+1 more2018-12-20
CVE-2018-1973 [HIGH] CWE-269 CVE-2018-1973: IBM API Connect 5.0.0.0 through 5.0.8.4 allows a user with limited 'API Administrator level access t IBM API Connect 5.0.0.0 through 5.0.8.4 allows a user with limited 'API Administrator level access to give themselves full 'Administrator' level access through the members functionality. IBM X-Force ID: 153914.
nvd
CVE-2020-4638P3HIGHCVSS 7.2≥ 2018.4.1.0, ≤ 2018.4.1.12v2018.4.1.0+1 more2020-09-03
CVE-2020-4638 [HIGH] CVE-2020-4638: IBM API Connect's API Manager 2018.4.1.0 through 2018.4.1.12 is vulnerable to privilege escalation. IBM API Connect's API Manager 2018.4.1.0 through 2018.4.1.12 is vulnerable to privilege escalation. An invitee to an API Provider organization can escalate privileges by manipulating the invitation link. IBM X-Force ID: 185508.
nvd
CVE-2020-4695P3HIGHCVSS 7.5≥ 10.0.0.0, ≤ 10.0.1.0v10.0.0.0+1 more2021-03-08
CVE-2020-4695 [HIGH] CWE-319 CVE-2020-4695: IBM API Connect V10 is impacted by insecure communications during database replication. As the data IBM API Connect V10 is impacted by insecure communications during database replication. As the data replication happens over insecure communication channels, an attacker can view unencrypted data leading to a loss of confidentiality.
nvd
CVE-2018-1858P3HIGHCVSS 8.8≥ 5.0.0.0, ≤ 5.0.8.6v5.0.0.0+1 more2019-06-25
CVE-2018-1858 [HIGH] CWE-352 CVE-2018-1858: IBM API Connect 5.0.0.0 through 5.0.8.6 is vulnerable to cross-site request forgery which could allo IBM API Connect 5.0.0.0 through 5.0.8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 151256.
nvd
CVE-2018-1779P3HIGHCVSS 7.5≥ 2018.1.0, ≤ 2018.3.7v2018.1+1 more2018-11-20
CVE-2018-1779 [HIGH] CWE-770 CVE-2018-1779: IBM API Connect 2018.1 through 2018.3.7 could allow an unauthenticated attacker to cause a denial of IBM API Connect 2018.1 through 2018.3.7 could allow an unauthenticated attacker to cause a denial of service due to not setting limits on JSON payload size. IBM X-Force ID: 148802.
nvd
CVE-2019-4256P3HIGHCVSS 7.5≥ 5.0.0.0, ≤ 5.0.8.6v5.0.0.0+1 more2019-05-29
CVE-2019-4256 [HIGH] CWE-326 CVE-2019-4256: IBM API Connect 5.0.0.0 through 5.0.8.6 uses weaker than expected cryptographic algorithms that coul IBM API Connect 5.0.0.0 through 5.0.8.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 159944.
nvd
CVE-2018-2007P3HIGHCVSS 7.5≥ 2018.1.0, ≤ 2018.4.1.2v2018.1+1 more2019-04-29
CVE-2018-2007 [HIGH] CWE-326 CVE-2018-2007: IBM API Connect 2018.1 and 2018.4.1.2 uses weaker than expected cryptographic algorithms that could IBM API Connect 2018.1 and 2018.4.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 155078.
nvd
CVE-2020-4452P3HIGHCVSS 7.5≥ 2018.4.1.0, ≤ 2018.4.1.11v2018.4.1.0+1 more2020-06-29
CVE-2020-4452 [HIGH] CWE-327 CVE-2020-4452: IBM API Connect V2018.4.1.0 through 2018.4.1.11 uses weaker than expected cryptographic algorithms t IBM API Connect V2018.4.1.0 through 2018.4.1.11 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 181324.
nvd
CVE-2019-4553P3HIGHCVSS 7.5≥ 5.0.0.0, ≤ 5.0.8.73v5.0.0.0+1 more2020-03-24
CVE-2019-4553 [HIGH] CWE-327 CVE-2019-4553: IBM API Connect V5.0.0.0 through 5.0.8.7iFix3 uses weaker than expected cryptographic algorithms tha IBM API Connect V5.0.0.0 through 5.0.8.7iFix3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 165958.
nvd
CVE-2019-4609P3HIGHCVSS 7.5v2018.4.1.72019-12-18
CVE-2019-4609 [HIGH] CWE-327 CVE-2019-4609: IBM API Connect 2018.4.1.7 uses weaker than expected cryptographic algorithms that could allow an at IBM API Connect 2018.4.1.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 168510.
nvd
CVE-2018-1774P3HIGHCVSS 7.8≥ 5.0.0.0, ≤ 5.0.8.4≥ 2018.1.0, ≤ 2018.3.6+4 more2018-11-09
CVE-2018-1774 [HIGH] CWE-1236 CVE-2018-1774: IBM API Connect 5.0.0.0, 5.0.8.4, 2018.1 and 2018.3.6 is vulnerable to CSV injection via the develop IBM API Connect 5.0.0.0, 5.0.8.4, 2018.1 and 2018.3.6 is vulnerable to CSV injection via the developer portal and analytics that could contain malicious commands that would be executed once opened by an administrator. IBM X-Force ID: 148692.
nvd
CVE-2019-4402P3HIGHCVSS 7.5≥ 2018.1.0, ≤ 2018.4.1.6v2018.1+1 more2019-08-20
CVE-2019-4402 [HIGH] CVE-2019-4402: IBM API Connect 2018.1 through 2018.4.1.6 developer portal could allow an unauthorized user to cause IBM API Connect 2018.1 through 2018.4.1.6 developer portal could allow an unauthorized user to cause a denial of service via an unprotected API. IBM X-Force ID: 162263.
nvd
CVE-2019-4382P4MEDIUMCVSS 5.3≥ 5.0.0.0, ≤ 5.0.8.6v5.0.0.0+1 more2019-06-25
CVE-2019-4382 [MEDIUM] CWE-319 CVE-2019-4382: IBM API Connect 5.0.0.0 through 5.0.8.6 could allow an unauthorized user to obtain sensitive informa IBM API Connect 5.0.0.0 through 5.0.8.6 could allow an unauthorized user to obtain sensitive information about the system users using specially crafted HTTP requests. IBM X-Force ID: 162162.
nvd
CVE-2018-2009P4MEDIUMCVSS 6.5≥ 2018.1.0, ≤ 2018.4.1.0v2018.1+1 more2019-03-11
CVE-2018-2009 [MEDIUM] CWE-200 CVE-2018-2009: IBM API Connect v2018.1 and 2018.4.1 is affected by an information disclosure vulnerability in the c IBM API Connect v2018.1 and 2018.4.1 is affected by an information disclosure vulnerability in the consumer API. Any registered user can obtain a list of all other users in all other orgs, including email id/names, etc. IBM X-Force ID: 155148.
nvd
CVE-2018-1389P4MEDIUMCVSS 6.5≥ 5.0.0.0, ≤ 5.0.8.2v5.0.1.0+17 more2018-04-30
CVE-2018-1389 [MEDIUM] CVE-2018-1389: IBM API Connect 5.0.0.0 through 5.0.8.2 is impacted by generated LoopBack APIs for a Model using the IBM API Connect 5.0.0.0 through 5.0.8.2 is impacted by generated LoopBack APIs for a Model using the BelongsTo/HasMany relationship allowing unauthorized modification of information. IBM X-Force ID: 138213.
nvd
Ibm Api Connect vulnerabilities | cvebase