PublicCVE

CVE-2019-4202

CRITICAL10.0JSON exportCreate alert

Description

IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal is vulnerable to command injection. An attacker with a specially crafted request can run arbitrary code on the server and gain complete access to the system. IBM X-Force ID: 159123.

CVSS breakdown

CVSS 3.0
Confidentiality
High
Integrity
High
Attack Complexity
Low
User Interaction
None
Attack Vector
Network
Scope
Changed
Availability
High
Privileges Required
None
RL
O
E
Unchanged
RC
Changed

Affected products