cbcvebase.

Ibm Api Connect vulnerabilities

81 known vulnerabilities affecting ibm/api_connect.

Total CVEs
81
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL14HIGH22MEDIUM44LOW1

Vulnerabilities

Page 4 of 5
CVE-2020-4838P4MEDIUMCVSS 5.4≥ 5.0.0.0, ≤ 5.0.8.10v5.0.0.0+1 more2021-01-12
CVE-2020-4838 [MEDIUM] CWE-79 CVE-2020-4838: IBM API Connect 5.0.0.0 through 5.0.8.10 is vulnerable to stored cross-site scripting. This vulnerab IBM API Connect 5.0.0.0 through 5.0.8.10 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190036.
nvd
CVE-2023-47722P4MEDIUMCVSS 5.5v10.0.5.3v10.0.6.0+1 more2023-12-09
CVE-2023-47722 [MEDIUM] CWE-522 CVE-2023-47722: IBM API Connect V10.0.5.3 and V10.0.6.0 stores user credentials in browser cache which can be read b IBM API Connect V10.0.5.3 and V10.0.6.0 stores user credentials in browser cache which can be read by a local user. IBM X-Force ID: 271912.
nvd
CVE-2018-1976P4MEDIUMCVSS 4.9≥ 5.0.0.0, ≤ 5.0.8.4v5.0.0.0+1 more2019-01-29
CVE-2018-1976 [MEDIUM] CWE-200 CVE-2018-1976: IBM API Connect 5.0.0.0 through 5.0.8.4 is impacted by sensitive information disclosure via a REST A IBM API Connect 5.0.0.0 through 5.0.8.4 is impacted by sensitive information disclosure via a REST API that could allow a user with administrative privileges to obtain highly sensitive information. IBM X-Force ID: 154031.
nvd
CVE-2020-4825P4MEDIUMCVSS 5.4≥ 2018.4.1.0, ≤ 2018.4.1.13v10.0.0.0+3 more2021-02-04
CVE-2020-4825 [MEDIUM] CWE-79 CVE-2020-4825: IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross- IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 189839.
nvd
CVE-2019-4444P4MEDIUMCVSS 5.5≥ 2018.1.0, ≤ 2018.4.1.7v2018.4.1.0+1 more2019-12-16
CVE-2019-4444 [MEDIUM] CWE-200 CVE-2019-4444: IBM API Connect 2018.1 through 2018.4.1.7 Developer Portal's user registration page does not disable IBM API Connect 2018.1 through 2018.4.1.7 Developer Portal's user registration page does not disable password autocomplete. An attacker with access to the browser instance and local system credentials can steal the credentials used for registration. IBM X-Force ID: 163453.
nvd
CVE-2020-4707P4MEDIUMCVSS 5.4≥ 5.0.0.0, ≤ 5.0.8.11v5.0.0.0+1 more2021-08-04
CVE-2020-4707 [MEDIUM] CWE-79 CVE-2020-4707: IBM API Connect 5.0.0.0 through 5.0.8.11 is vulnerable to cross-site scripting. This vulnerability a IBM API Connect 5.0.0.0 through 5.0.8.11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 187370.
nvd
CVE-2018-1430P4MEDIUMCVSS 5.4≥ 5.0.0.0, ≤ 5.0.8.2v5.0.1.0+18 more2018-04-30
CVE-2018-1430 [MEDIUM] CWE-79 CVE-2018-1430: IBM API Connect 5.0.0.0 through 5.0.8.2 is vulnerable to cross-site scripting. This vulnerability al IBM API Connect 5.0.0.0 through 5.0.8.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139226.
nvd
CVE-2020-4251P4MEDIUMCVSS 5.4≥ 5.0.0.0, ≤ 5.0.8.8v5.0.0.0+1 more2020-06-12
CVE-2020-4251 [MEDIUM] CWE-79 CVE-2020-4251: IBM API Connect 5.0.0.0 through 5.0.8.8 is vulnerable to cross-site scripting. This vulnerability al IBM API Connect 5.0.0.0 through 5.0.8.8 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 175489.
nvd
CVE-2018-1382P4MEDIUMCVSS 5.4≥ 5.0.0.0, ≤ 5.0.6.4v5.0.7.0+16 more2018-02-07
CVE-2018-1382 [MEDIUM] CWE-79 CVE-2018-1382: IBM API Connect 5.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to em IBM API Connect 5.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138079.
nvd
CVE-2018-1859P4MEDIUMCVSS 4.7≥ 5.0.0.0, ≤ 5.0.8.4v5.0.0.0+1 more2019-01-04
CVE-2018-1859 [MEDIUM] CVE-2018-1859: IBM API Connect 5.0.0.0 through 5.0.8.4 could allow a user authenticated as an administrator with li IBM API Connect 5.0.0.0 through 5.0.8.4 could allow a user authenticated as an administrator with limited rights to escalate their privileges. IBM X-Force ID: 151258.
nvd
CVE-2021-20440P4MEDIUMCVSS 4.3≥ 2018.4.1.0, ≤ 2018.4.1.13v10.0.0.0+2 more2021-03-15
CVE-2021-20440 [MEDIUM] CVE-2021-20440: IBM API Connect 10.0.0.0, and 2018.4.1.0 through 2018.4.1.13 does not restrict member registration t IBM API Connect 10.0.0.0, and 2018.4.1.0 through 2018.4.1.13 does not restrict member registration to the intended recepient. An attacker who is a valid user in the user registry used by API Manager can use a stolen invitation link and register themselves as a member of an API provider organization. IBM X-Force ID: 196536.
nvd
CVE-2018-1532P4MEDIUMCVSS 4.3≥ 5.0.0.0, ≤ 5.0.8.2v5.0.1.0+18 more2018-05-31
CVE-2018-1532 [MEDIUM] CWE-200 CVE-2018-1532: IBM API Connect 5.0.0.0 through 5.0.8.2 does not properly update the SESSIONID with each request, wh IBM API Connect 5.0.0.0 through 5.0.8.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 142430.
nvd
CVE-2018-1468P4MEDIUMCVSS 4.3v5.0.8.1v5.0.8.22018-05-02
CVE-2018-1468 [MEDIUM] CWE-200 CVE-2018-1468: IBM API Connect 5.0.8.1 and 5.0.8.2 could allow a user to get access to internal environment and sen IBM API Connect 5.0.8.1 and 5.0.8.2 could allow a user to get access to internal environment and sensitive API details to which they are not authorized. IBM X-Force ID: 140399.
nvd
CVE-2017-1785P4MEDIUMCVSS 4.3v5.0.7.0v5.0.7.1+3 more2018-02-07
CVE-2017-1785 [MEDIUM] CWE-200 CVE-2017-1785: IBM API Connect 5.0.7 and 5.0.8 could allow an authenticated remote user to modify query parameters IBM API Connect 5.0.7 and 5.0.8 could allow an authenticated remote user to modify query parameters to obtain sensitive information. IBM X-Force ID: 136859.
nvd
CVE-2017-1555P4MEDIUMCVSS 4.3v5.0.0.0v5.0.0.1+14 more2017-09-25
CVE-2017-1555 [MEDIUM] CWE-20 CVE-2017-1555: IBM API Connect 5.0.0.0 through 5.0.7.2 could allow an authenticated user to generate an API token w IBM API Connect 5.0.0.0 through 5.0.7.2 could allow an authenticated user to generate an API token when not subscribed to the application plan. IBM X-Force ID: 131545.
nvd
CVE-2018-1548P4MEDIUMCVSS 4.3≥ 2018.1.0.0, ≤ 2018.2.4v2018.1.0.0+4 more2018-07-09
CVE-2018-1548 [MEDIUM] CWE-200 CVE-2018-1548: IBM API Connect 2018.1.0.0, 2018.2.1, 2018.2.2, 2018.2.3, and 2018.2.4 contains a vulnerability that IBM API Connect 2018.1.0.0, 2018.2.1, 2018.2.2, 2018.2.3, and 2018.2.4 contains a vulnerability that could allow an authenticated user to obtain sensitive information. IBM X-Force ID: 142657.
nvd
CVE-2020-4827P4MEDIUMCVSS 4.3≥ 2018.4.1.0, ≤ 2018.4.1.13v10.0.0.0+3 more2021-02-04
CVE-2020-4827 [MEDIUM] CWE-352 CVE-2020-4827: IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross- IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 189841.
nvd
CVE-2020-4826P4MEDIUMCVSS 4.3≥ 2018.4.1.0, ≤ 2018.4.1.13v10.0.0.0+3 more2021-02-04
CVE-2020-4826 [MEDIUM] CWE-352 CVE-2020-4826: IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross- IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 189840.
nvd
CVE-2018-1874P4MEDIUMCVSS 4.6≥ 5.0.0.0, ≤ 5.0.8.5v5.0.0.0+1 more2019-04-02
CVE-2018-1874 [MEDIUM] CWE-200 CVE-2018-1874: IBM API Connect 5.0.0.0 through 5.0.8.5 could display highly sensitive information to an attacker wi IBM API Connect 5.0.0.0 through 5.0.8.5 could display highly sensitive information to an attacker with physical access to the system. IBM X-Force ID: 151636.
nvd
CVE-2020-4640P4MEDIUMCVSS 4.1≥ 2018.4.1.0, ≤ 2018.4.1.13v10.0.0.0+3 more2021-02-04
CVE-2020-4640 [MEDIUM] CWE-200 CVE-2020-4640: Certain IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 configurations Certain IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 configurations can result in sensitive information in the URL fragment identifiers. This information can be cached in the intermediate nodes like proxy servers, cdn, logging platforms, etc. An attacker can make use of this information to perform attacks by impersonatin
nvd
Ibm Api Connect vulnerabilities | cvebase