Description
IBM API Connect Developer Portal 5.0.0.0 through 5.0.8.2 could allow an unauthenticated attacker to execute system commands using specially crafted HTTP requests. IBM X-Force ID: 140605.
CVSS breakdown
CVSS 3.0
Availability
High
Attack Complexity
Low
Attack Vector
Network
Confidentiality
High
Integrity
High
Privileges Required
None
Scope
Unchanged
User Interaction
None
Affected products
- ibm / api_connect5.0.1.0 – 5.0.1.0
- ibm / api_connect5.0.0.0 – 5.0.0.0
- ibm / api_connect5.0.2.0 – 5.0.2.0
- ibm / api_connect5.0.5.0 – 5.0.5.0
- ibm / api_connect5.0.6.0 – 5.0.6.0
- ibm / api_connect5.0.6.1 – 5.0.6.1
- ibm / api_connect5.0.6.2 – 5.0.6.2
- ibm / api_connect5.0.7.0 – 5.0.7.0
- ibm / api_connect5.0.7.1 – 5.0.7.1
- ibm / api_connect5.0.3.0 – 5.0.3.0
- ibm / api_connect5.0.4.0 – 5.0.4.0
- ibm / api_connect5.0.7.2 – 5.0.7.2
- ibm / api_connect5.0.6.3 – 5.0.6.3
- ibm / api_connect5.0.6.4 – 5.0.6.4
- ibm / api_connect5.0.8.0 – 5.0.8.0
- ibm / api_connect5.0.8.1 – 5.0.8.1
- ibm / api_connect5.0.6.5 – 5.0.6.5
- ibm / api_connect5.0.6.6 – 5.0.6.6
- ibm / api_connect5.0.8.2 – 5.0.8.2