CVE-2019-4402
- EPSS 0.39%
- Published 20.08.2019 19:15:11
- Last modified 21.11.2024 04:43:33
IBM API Connect 2018.1 through 2018.4.1.6 developer portal could allow an unauthorized user to cause a denial of service via an unprotected API. IBM X-Force ID: 162263.
CVE-2019-4382
- EPSS 0.34%
- Published 25.06.2019 16:15:10
- Last modified 21.11.2024 04:43:31
IBM API Connect 5.0.0.0 through 5.0.8.6 could allow an unauthorized user to obtain sensitive information about the system users using specially crafted HTTP requests. IBM X-Force ID: 162162.
CVE-2018-2013
- EPSS 0.24%
- Published 25.06.2019 16:15:10
- Last modified 21.11.2024 04:03:35
IBM API Connect 2018.1 through 2018.4.1.5 could disclose sensitive information to an unauthorized user that could aid in further attacks against the system. IBM X-Force ID: 155193.
CVE-2018-2011
- EPSS 0.55%
- Published 25.06.2019 16:15:10
- Last modified 21.11.2024 04:03:35
IBM API Connect 2018.1 through 2018.4.1.5 could allow an attacker to obtain sensitive information from a specially crafted HTTP request that could aid an attacker in further attacks against the system. IBM X-Force ID: 155150.
CVE-2018-1858
- EPSS 0.18%
- Published 25.06.2019 16:15:10
- Last modified 21.11.2024 04:00:30
IBM API Connect 5.0.0.0 through 5.0.8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 151256.
CVE-2019-4256
- EPSS 0.16%
- Published 29.05.2019 15:29:00
- Last modified 21.11.2024 04:43:23
IBM API Connect 5.0.0.0 through 5.0.8.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 159944.
- EPSS 0.14%
- Published 22.05.2019 15:29:02
- Last modified 21.11.2024 04:00:42
IBM API Connect 5.0.0.0, and 5.0.8.6 could could return sensitive information that could provide critical information as to the underlying software stack in CMC UI headers. IBM X-Force ID: 154284.
CVE-2018-2015
- EPSS 0.2%
- Published 02.05.2019 16:29:00
- Last modified 21.11.2024 04:03:35
IBM API Connect 2018.1 and 2018.4.1.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click act...
CVE-2018-2007
- EPSS 0.1%
- Published 29.04.2019 17:29:00
- Last modified 21.11.2024 04:03:35
IBM API Connect 2018.1 and 2018.4.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 155078.
CVE-2019-4203
- EPSS 0.48%
- Published 15.04.2019 15:29:00
- Last modified 21.11.2024 04:43:18
IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal can be exploited by app developers to download arbitrary files from the host OS and potentially carry out SSRF attacks. IBM X-Force ID: 159124.