7.5

CVE-2017-1379

IBM API Connect 5.0.0.0 could allow a remote attacker to obtain sensitive information, caused by improper handling of requests to the Developer Portal. IBM X-Force ID: 127002.

Data is provided by the National Vulnerability Database (NVD)
IbmApi Connect Version5.0.0.0
IbmApi Connect Version5.0.0.1
IbmApi Connect Version5.0.1.0
IbmApi Connect Version5.0.2.0
IbmApi Connect Version5.0.3.0
IbmApi Connect Version5.0.4.0
IbmApi Connect Version5.0.5.0
IbmApi Connect Version5.0.6.0
IbmApi Connect Version5.0.6.1
IbmApi Connect Version5.0.6.2
IbmApi Connect Version5.0.7.0
IbmApi Connect Version5.0.7.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.31% 0.513
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.