Lucene search

K
ibmIBM3F0FAB10625AFF47B225FDF6B886A80481EA5F726F7A0F7A7DC665CB1D0D48DB
HistoryDec 18, 2018 - 9:30 p.m.

Security Bulletin: IBM API Connect is affected by a NoSQL Injection in MongoDB connector for the LoopBack framework (CVE-2018-1784)

2018-12-1821:30:01
www.ibm.com
13

EPSS

0.002

Percentile

51.9%

Summary

IBM API Connect has addressed the following vulnerabilities.

Vulnerability Details

CVEID:CVE-2018-1784
**DESCRIPTION:*IBM API Connect is affected by a NoSQL Injection in MongoDB connector for the LoopBack framework.
CVSS Base Score: 7.1
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/148807&gt; for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N)

Affected Products and Versions

Affected Product

|

Affected Versions

—|—

IBM API Connect

|

5.0.0.0-5.0.8.4

Remediation/Fixes

Affected Product

|

Addressed in****VRMF

|

APAR

|

Remediation / First Fix

—|—|—|—

IBM API Connect

5.0.0.0-5.0.8.4

| 5.0.8.5 fix pack |

LI80407

|

Addressed in IBM API Connect V5.0.8.5 fix pack.

Loopback framework is impacted.

Follow this link and find the APIConnect_Management V5.0.8.5 download.

http://www.ibm.com/support/fixcentral/swg/quickorder?parent=ibm%7EWebSphere&product=ibm/WebSphere/IBM+API+Connect&release=5.0.8.4&platform=All&function=all&source=fc

EPSS

0.002

Percentile

51.9%

Related for 3F0FAB10625AFF47B225FDF6B886A80481EA5F726F7A0F7A7DC665CB1D0D48DB