CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
LOW
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C
AI Score
Confidence
High
EPSS
Percentile
70.2%
IBM LoopBack (IBM API Connect 2018.1, 2018.4.1, 5.0.8.0, and 5.0.8.4) could allow an attacker to bypass authentication if the AccessToken Model is exposed over a REST API, it is then possible for anyone to create an AccessToken for any User provided they know the userId and can hence get access to the other user�s data / access to their privileges (if the user happens to be an Admin for example). IBM X-Force ID: 148801.
[
{
"product": "API Connect",
"vendor": "IBM",
"versions": [
{
"status": "affected",
"version": "5.0.8.0"
},
{
"status": "affected",
"version": "2018.1"
},
{
"status": "affected",
"version": "5.0.8.4"
},
{
"status": "affected",
"version": "2018.4.1"
}
]
}
]
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
LOW
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C
AI Score
Confidence
High
EPSS
Percentile
70.2%