Overview
- Description
- IBM LoopBack (IBM API Connect 2018.1, 2018.4.1, 5.0.8.0, and 5.0.8.4) could allow an attacker to bypass authentication if the AccessToken Model is exposed over a REST API, it is then possible for anyone to create an AccessToken for any User provided they know the userId and can hence get access to the other user’s data / access to their privileges (if the user happens to be an Admin for example). IBM X-Force ID: 148801.
- Source
- psirt@us.ibm.com
- NVD status
- Modified
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 8.1
- Impact score
- 5.9
- Exploitability score
- 2.2
- Vector string
- CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 9.3
- Impact score
- 10
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-287
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:api_connect:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2EE04F67-2883-4840-9574-7363C3CD618E", "versionEndIncluding": "5.0.8.4", "versionStartIncluding": "5.0.8.0" }, { "criteria": "cpe:2.3:a:ibm:api_connect:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7C567025-9080-4C12-9F27-005B2A7F5149", "versionEndIncluding": "2018.4.1.0", "versionStartIncluding": "2018.1.0" } ], "operator": "OR" } ] } ]