cbcvebase.

Ibm Api Connect vulnerabilities

81 known vulnerabilities affecting ibm/api_connect.

Total CVEs
81
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL14HIGH22MEDIUM44LOW1

Vulnerabilities

Page 3 of 5
CVE-2020-4828P4MEDIUMCVSS 6.5≥ 2018.4.1.0, ≤ 2018.4.1.13v10.0.0.0+3 more2021-02-04
CVE-2020-4828 [MEDIUM] CWE-20 CVE-2020-4828: IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to web ca IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to web cache poisoning, caused by improper input validation by modifying HTTP request headers. IBM X-Force ID: 189842.
nvd
CVE-2017-1556P4MEDIUMCVSS 6.5v5.0.7.0v5.0.7.1+1 more2017-09-13
CVE-2017-1556 [MEDIUM] CWE-20 CVE-2017-1556: IBM API Connect 5.0.7.0 through 5.0.7.2 is vulnerable to a regular expression attack that could allo IBM API Connect 5.0.7.0 through 5.0.7.2 is vulnerable to a regular expression attack that could allow an authenticated attacker to use a regex and cause the system to slow or hang. IBM X-Force ID: 131546.
nvd
CVE-2020-4903P4MEDIUMCVSS 6.5≥ 10.0.0.0, < 10.0.1.1≥ 2018.4.1.0, < 2018.4.1.13+4 more2021-03-08
CVE-2020-4903 [MEDIUM] CVE-2020-4903: IBM API Connect V10 and V2018 could allow an attacker who has intercepted a registration invitation IBM API Connect V10 and V2018 could allow an attacker who has intercepted a registration invitation link to impersonate the registered user or obtain sensitive information. IBM X-Force ID: 191105.
nvd
CVE-2017-1328P4MEDIUMCVSS 5.3v5.0.0.0v5.0.0.1+8 more2017-06-27
CVE-2017-1328 [MEDIUM] CVE-2017-1328: IBM API Connect 5.0.0.0 - 5.0.6.0 could allow a remote attacker to bypass security restrictions of t IBM API Connect 5.0.0.0 - 5.0.6.0 could allow a remote attacker to bypass security restrictions of the api, caused by improper handling of security policy. By crafting a suitable request, an attacker could exploit this vulnerability to bypass security and use the vulnerable API. IBM X-Force ID: 126230.
nvd
CVE-2020-4337P4MEDIUMCVSS 6.5≥ 2018.4.1.0, ≤ 2018.4.1.12v2018.4.1.0+1 more2020-09-03
CVE-2020-4337 [MEDIUM] CVE-2020-4337: IBM API Connect 2018.4.1.0 through 2018.4.1.12 could allow an attacker to launch phishing attacks by IBM API Connect 2018.4.1.0 through 2018.4.1.12 could allow an attacker to launch phishing attacks by tricking the server to generate user registration emails that contain malicious URLs. IBM X-Force ID: 177933.
nvd
CVE-2018-1546P4MEDIUMCVSS 5.9≥ 5.0.0.0, ≤ 5.0.8.3v5.0.1.0+19 more2018-07-06
CVE-2018-1546 [MEDIUM] CWE-200 CVE-2018-1546: IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to obtain sensitive informatio IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 142650.
nvd
CVE-2018-2011P4MEDIUMCVSS 5.3≥ 2018.1.0, ≤ 2018.4.1.5v2018.1+1 more2019-06-25
CVE-2018-2011 [MEDIUM] CWE-200 CVE-2018-2011: IBM API Connect 2018.1 through 2018.4.1.5 could allow an attacker to obtain sensitive information fr IBM API Connect 2018.1 through 2018.4.1.5 could allow an attacker to obtain sensitive information from a specially crafted HTTP request that could aid an attacker in further attacks against the system. IBM X-Force ID: 155150.
nvd
CVE-2020-4706P4MEDIUMCVSS 5.4≥ 5.0.0.0, ≤ 5.0.8.10v5.0.0.0+1 more2021-08-17
CVE-2020-4706 [MEDIUM] CWE-79 CVE-2020-4706: IBM API Connect 5.0.0.0 through 5.0.8.10 is vulnerable to HTTP header injection, caused by improper IBM API Connect 5.0.0.0 through 5.0.8.10 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to inject HTTP HOST header, which will allow the attacker to conduct various attacks against the vulnerable system, in
nvd
CVE-2018-2015P4MEDIUMCVSS 6.1≥ 2018.1.0, ≤ 2018.4.1.4v2018.1+1 more2019-05-02
CVE-2018-2015 [MEDIUM] CWE-20 CVE-2018-2015: IBM API Connect 2018.1 and 2018.4.1.4 could allow a remote attacker to hijack the clicking action of IBM API Connect 2018.1 and 2018.4.1.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 155195.
nvd
CVE-2017-1386P4MEDIUMCVSS 5.9v5.0.0.0v5.0.0.1+10 more2017-07-31
CVE-2017-1386 [MEDIUM] CWE-521 CVE-2017-1386: IBM API Connect 5.0.0.0 could allow a user to bypass policy restrictions and create non-compliant pa IBM API Connect 5.0.0.0 could allow a user to bypass policy restrictions and create non-compliant passwords which could be intercepted and decrypted using man in the middle techniques. IBM X-Force ID: 127160.
nvd
CVE-2019-4051P4MEDIUMCVSS 5.3≥ 2018.1.0, ≤ 2018.4.1.3v2018.1+1 more2019-04-08
CVE-2019-4051 [MEDIUM] CWE-200 CVE-2019-4051: Some URIs in IBM API Connect 2018.1 and 2018.4.1.3 disclose system specification information like th Some URIs in IBM API Connect 2018.1 and 2018.4.1.3 disclose system specification information like the machine id, system uuid, filesystem paths, network interface names along with their mac addresses. An attacker can use this information in targeted attacks. IBM X-Force ID: 156542.
nvd
CVE-2019-4600P4MEDIUMCVSS 5.3≥ 5.0.0.0, ≤ 5.0.8.7v5.0.0.0+1 more2019-10-29
CVE-2019-4600 [MEDIUM] CVE-2019-4600: IBM API Connect version V5.0.0.0 through 5.0.8.7 could reveal sensitive information to an attacker u IBM API Connect version V5.0.0.0 through 5.0.8.7 could reveal sensitive information to an attacker using a specially crafted HTTP request. IBM X-Force ID: 167883.
nvd
CVE-2016-1000232P4MEDIUMCVSS 5.3≥ 5.0.6.0, ≤ 5.0.6.5≥ 5.0.7.0, ≤ 5.0.7.2+1 more2018-09-05
CVE-2016-1000232 [MEDIUM] CWE-20 CVE-2016-1000232: NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP reques NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial of Service. This attack appear to be exploitable via Custom HTTP header passed by client. This vulnerability appears to have been fixed in 2.3.0.
nvd
CVE-2018-2013P4MEDIUMCVSS 5.3≥ 2018.1.0, ≤ 2018.4.1.5v2018.1+1 more2019-06-25
CVE-2018-2013 [MEDIUM] CWE-200 CVE-2018-2013: IBM API Connect 2018.1 through 2018.4.1.5 could disclose sensitive information to an unauthorized us IBM API Connect 2018.1 through 2018.4.1.5 could disclose sensitive information to an unauthorized user that could aid in further attacks against the system. IBM X-Force ID: 155193.
nvd
CVE-2019-4437P4MEDIUMCVSS 5.3≥ 2018.1.0, ≤ 2018.4.1.6v2018.1+1 more2019-08-20
CVE-2019-4437 [MEDIUM] CWE-200 CVE-2019-4437: IBM API Connect 2018.1 through 2018.4.1.6 may inadvertently leak sensitive details about internal se IBM API Connect 2018.1 through 2018.4.1.6 may inadvertently leak sensitive details about internal servers and network via API swagger. IBM X-force ID: 162947.
nvd
CVE-2021-38997P4MEDIUMCVSS 5.4≥ 10.0.0.0, ≤ 10.0.5.0≥ 10.0.1.0, ≤ 10.0.1.7+4 more2022-12-12
CVE-2021-38997 [MEDIUM] CWE-644 CVE-2021-38997: IBM API Connect V10.0.0.0 through V10.0.5.0, V10.0.1.0 through V10.0.1.7, and V2018.4.1.0 through 20 IBM API Connect V10.0.0.0 through V10.0.5.0, V10.0.1.0 through V10.0.1.7, and V2018.4.1.0 through 2018.4.1.19 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or ses
nvd
CVE-2020-4346P4MEDIUMCVSS 5.3≥ 2018.4.1.0, ≤ 2018.4.1.10v2018.4.1.0+1 more2020-05-12
CVE-2020-4346 [MEDIUM] CVE-2020-4346: IBM API Connect's V2018.4.1.0 through 2018.4.1.10 management server has an unsecured api which can b IBM API Connect's V2018.4.1.0 through 2018.4.1.10 management server has an unsecured api which can be exploited by an unauthenticated attacker to obtain sensitive information. IBM X-Force ID: 178322.
nvd
CVE-2017-1551P4MEDIUMCVSS 6.1v5.0.0.0v5.0.0.1+13 more2017-09-25
CVE-2017-1551 [MEDIUM] CWE-20 CVE-2017-1551: IBM API Connect 5.0.0.0 through 5.0.7.2 could allow a remote attacker to hijack the clicking action IBM API Connect 5.0.0.0 through 5.0.7.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 131291.
nvd
CVE-2018-1599P4MEDIUMCVSS 5.4≥ 5.0.0.0, ≤ 5.0.8.3≥ 2018.1, ≤ 2018.3.4+20 more2018-08-22
CVE-2018-1599 [MEDIUM] CWE-20 CVE-2018-1599: IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to hijack the clicking action IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 143744.
nvd
CVE-2020-4195P4MEDIUMCVSS 5.4≥ 2018.4.1.0, ≤ 2018.4.1.10v2018.4.1.0+1 more2020-05-12
CVE-2020-4195 [MEDIUM] CWE-1021 CVE-2020-4195: IBM API Connect V2018.4.1.0 through 2018.4.1.10 could allow a remote attacker to hijack the clicking IBM API Connect V2018.4.1.0 through 2018.4.1.10 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 174859.
nvd
Ibm Api Connect vulnerabilities | cvebase