- EPSS 0.3%
- Published 20.12.2018 14:29:00
- Last modified 21.11.2024 04:00:40
IBM API Connect 5.0.0.0 through 5.0.8.4 allows a user with limited 'API Administrator level access to give themselves full 'Administrator' level access through the members functionality. IBM X-Force ID: 153914.
CVE-2018-1784
- EPSS 0.26%
- Published 20.12.2018 14:29:00
- Last modified 21.11.2024 04:00:21
IBM API Connect 5.0.0.0 and 5.0.8.4 is affected by a NoSQL Injection in MongoDB connector for the LoopBack framework. IBM X-Force ID: 148807.
CVE-2018-1778
- EPSS 0.36%
- Published 20.12.2018 14:29:00
- Last modified 21.11.2024 04:00:21
IBM LoopBack (IBM API Connect 2018.1, 2018.4.1, 5.0.8.0, and 5.0.8.4) could allow an attacker to bypass authentication if the AccessToken Model is exposed over a REST API, it is then possible for anyone to create an AccessToken for any User provided ...
CVE-2018-1779
- EPSS 0.39%
- Published 20.11.2018 14:29:00
- Last modified 21.11.2024 04:00:21
IBM API Connect 2018.1 through 2018.3.7 could allow an unauthenticated attacker to cause a denial of service due to not setting limits on JSON payload size. IBM X-Force ID: 148802.
CVE-2018-1774
- EPSS 0.18%
- Published 09.11.2018 01:29:00
- Last modified 21.11.2024 04:00:20
IBM API Connect 5.0.0.0, 5.0.8.4, 2018.1 and 2018.3.6 is vulnerable to CSV injection via the developer portal and analytics that could contain malicious commands that would be executed once opened by an administrator. IBM X-Force ID: 148692.
CVE-2018-1789
- EPSS 0.18%
- Published 07.09.2018 15:29:00
- Last modified 21.11.2024 04:00:22
IBM API Connect v2018.1.0 through v2018.3.4 could allow an attacker to send a specially crafted request to conduct a server side request forgery attack. IBM X-Force ID: 148939.
CVE-2016-1000232
- EPSS 0.92%
- Published 05.09.2018 17:29:00
- Last modified 21.11.2024 02:43:01
NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial of Service. This attack appear to be exploitable via Custom HTTP header passed by client. This vulne...
CVE-2018-1599
- EPSS 0.09%
- Published 22.08.2018 11:29:00
- Last modified 21.11.2024 04:00:04
IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click a...
CVE-2018-1712
- EPSS 0.11%
- Published 16.08.2018 19:29:00
- Last modified 21.11.2024 04:00:14
IBM API Connect's Developer Portal 5.0.0.0 through 5.0.8.3 is vulnerable to Server Side Request Forgery. An attacker, using specially crafted input parameters can trick the server into making potentially malicious calls within the trusted network. IB...
CVE-2018-1638
- EPSS 0.21%
- Published 31.07.2018 13:29:00
- Last modified 21.11.2024 04:00:07
IBM API Connect 5.0.0.0-5.0.8.3 Developer Portal does not enforce Two Factor Authentication (TFA) while resetting a user password but enforces it for all other login scenarios. IBM X-Force ID: 144483.