CVE-2018-1712

IBM API Connect's Developer Portal 5.0.0.0 through 5.0.8.3 is vulnerable to Server Side Request Forgery. An attacker, using specially crafted input parameters can trick the server into making potentially malicious calls within the trusted network. IBM X-Force ID: 146370.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ibm:api_connect:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:00

Type Values Removed Values Added
CVSS v2 : 7.5
v3 : 9.9
v2 : 7.5
v3 : 8.6
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/146370 - VDB Entry, Vendor Advisory () https://exchange.xforce.ibmcloud.com/vulnerabilities/146370 - VDB Entry, Vendor Advisory
References () https://www-01.ibm.com/support/docview.wss?uid=ibm10716169 - Vendor Advisory () https://www-01.ibm.com/support/docview.wss?uid=ibm10716169 - Vendor Advisory

Information

Published : 2018-08-16 19:29

Updated : 2024-11-21 04:00


NVD link : CVE-2018-1712

Mitre link : CVE-2018-1712

CVE.ORG link : CVE-2018-1712


JSON object : View

Products Affected

ibm

  • api_connect
CWE
CWE-352

Cross-Site Request Forgery (CSRF)