Description
IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal can be exploited by app developers to download arbitrary files from the host OS and potentially carry out SSRF attacks. IBM X-Force ID: 159124.
CVSS breakdown
CVSS 3.0
Integrity
Low
Confidentiality
High
Attack Complexity
Low
User Interaction
Required
Scope
Changed
Availability
High
Privileges Required
Low
Attack Vector
Network
E
Unchanged
RL
O
RC
Changed
Affected products
- ibm / api_connect5.0.0.0 – 5.0.0.0
- ibm / api_connect5.0.8.6 – 5.0.8.6