Description
IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal is vulnerable to command injection. An attacker with a specially crafted request can run arbitrary code on the server and gain complete access to the system. IBM X-Force ID: 159123.
CVSS breakdown
CVSS 3.0
Confidentiality
High
Integrity
High
Attack Complexity
Low
User Interaction
None
Attack Vector
Network
Scope
Changed
Availability
High
Privileges Required
None
RL
O
E
Unchanged
RC
Changed
Affected products
- ibm / api_connect5.0.0.0 – 5.0.0.0
- ibm / api_connect5.0.8.6 – 5.0.8.6