Lucene search

K
ibmIBM6A91952ED83D4B9FC380038F409F8EF7F46FF13AA9FB54899BCAA89FDDF7E4EC
HistoryFeb 01, 2019 - 10:20 p.m.

Security Bulletin: API Connect V2018 is impacted by access token leak (CVE-2019-4008)

2019-02-0122:20:01
www.ibm.com
5

0.007 Low

EPSS

Percentile

80.3%

Summary

IBM API Connect has addressed the following vulnerability.

Vulnerability Details

CVEID: CVE-2019-4008
**DESCRIPTION:*API Connect V2018 is impacted by access token leak. Authorization tokens in some URLs can result in the tokens being written to log files.
CVSS Base Score: 9
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/155626&gt; for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)

Affected Products and Versions

Affected IBM API Management Affected Versions
IBM API Connect 2018.1-2018.4.1.1

Remediation/Fixes

Affected releases Fixed in VRMF APAR Remediation / First Fix
IBM API Connect V2018.1 - 2018.4.1.1 2018.4.1.2 LI80527

Addressed in IBM API Connect v2018.4.1.2 fixpack.

Follow this link and find the appropriate form factor for your installation: “management” or apicup* or ICP for 2018.4.1.2.

http://www.ibm.com/support/fixcentral/swg/quickorder?parent=ibm%7EWebSphere&product=ibm/WebSphere/IBM+API+Connect&release=2018.4.1.1&platform=All&function=all&source=fc

Workarounds and Mitigations

None

0.007 Low

EPSS

Percentile

80.3%

Related for 6A91952ED83D4B9FC380038F409F8EF7F46FF13AA9FB54899BCAA89FDDF7E4EC