Lucene search

K
ibmIBM7955012CEE8E468038AC5BE771E857607E98720432B7F7A93E56EEB7EB814D45
HistoryApr 10, 2019 - 4:30 p.m.

Security Bulletin: IBM API Connect's Developer Portal(V5) is vulnerable to command injection (CVE-2019-4202)

2019-04-1016:30:01
www.ibm.com
10

0.003 Low

EPSS

Percentile

71.1%

Summary

IBM API Connect has addressed the following vulnerability.

Vulnerability Details

CVEID:CVE-2019-4202
**DESCRIPTION:*IBM API Connect’s Developer Portal is vulnerable to command injection. An attacker with a specially crafted request can run arbitrary code on the server and gain complete access to the system.
CVSS Base Score: 10
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/159123&gt; for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)

Affected Products and Versions

IBM API Connect version V5.0.0.0-5.0.8.6

Remediation/Fixes

Affected Product Addressed in VRMF APAR Remediation/First Fix

IBM API Connect

V5.0.0.0-5.0.8.6

| 5.0.8.6 iFix |

LI80748

|

Addressed in IBM API Connect 5.0.8.6 iFix.

Follow this link and find the developer portal package.

http://www.ibm.com/support/fixcentral/swg/quickorder?parent=ibm%7EWebSphere&product=ibm/WebSphere/IBM+API+Connect&release=5.0.8.5&platform=All&function=fixId&fixids=5.0.8.6-iFix-APIConnect-Portal-Ubuntu16-20190410-1407,5.0.8.6-iFix-APIConnect-Portal-Ubuntu16-20190410-1407.ova&includeSupersedes=0&source=fc

Workarounds and Mitigations

None

0.003 Low

EPSS

Percentile

71.1%

Related for 7955012CEE8E468038AC5BE771E857607E98720432B7F7A93E56EEB7EB814D45