PT-2019-16865 · Ibm · Ibm Api Connect

CVE-2019-4052

·

Published

2019-03-22

·

Updated

2023-02-03

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM API Connect versions 2018.1 through 2018.4.1.2
Description The issue allows unauthenticated users to discover login ids of registered users by leveraging IBM API Connect apis.
Recommendations For IBM API Connect versions 2018.1 through 2018.4.1.2, consider restricting access to the affected apis to prevent unauthenticated users from discovering login ids of registered users.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-4052

Affected Products

Ibm Api Connect