Vulnerability CVE-2018-1712


Published: 2018-08-16

Description:
IBM API Connect's Developer Portal 5.0.0.0 through 5.0.8.3 is vulnerable to Server Side Request Forgery. An attacker, using specially crafted input parameters can trick the server into making potentially malicious calls within the trusted network. IBM X-Force ID: 146370.

Type:

CWE-352

(Cross-Site Request Forgery (CSRF))

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
IBM -> Api connect 

 References:
https://exchange.xforce.ibmcloud.com/vulnerabilities/146370
https://www-01.ibm.com/support/docview.wss?uid=ibm10716169

Copyright 2024, cxsecurity.com

 

Back to Top