Overview
- Description
- IBM API Connect (aka APIConnect) before 5.0.3.0 with NPM before 2.2.8 includes certain internal server credentials in the software package, which might allow remote attackers to bypass intended access restrictions by leveraging knowledge of these credentials.
- Source
- psirt@us.ibm.com
- NVD status
- Analyzed
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-200
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:api_connect:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FA40C19A-1327-45BF-8CAA-7813912A2696", "versionEndIncluding": "5.0.2.0" }, { "criteria": "cpe:2.3:a:ibm:network_path_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0BFC6336-21EF-4327-80E2-E75F0E6A1ED1", "versionEndIncluding": "2.1.1.9" } ], "operator": "OR" } ] } ]