PublicCVE

CVE-2019-4155

HIGH8.8JSON exportCreate alert

Description

IBM API Connect's Developer Portal 2018.1 and 2018.4.1.3 is impacted by a privilege escalation vulnerability when integrated with an OpenID Connect (OIDC) user registry. IBM X-Force ID: 158544.

CVSS breakdown

CVSS 3.0
Attack Complexity
Low
Confidentiality
High
Privileges Required
Low
Availability
High
Integrity
High
Attack Vector
Network
Scope
Unchanged
User Interaction
None
RC
Changed
RL
O
E
Unchanged

Affected products