IBM API Connect has addressed the following vulnerability which allows the possibility of bypassing password policy.
CVEID:CVE-2017-1386**
DESCRIPTION: *IBM API Connect could allow a user to bypass policy restrictions and create non-compliant passwords which could be intercepted and decrypted using man in the middle techniques.
CVSS Base Score: 5.9
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/127160 for the current score
CVSS Environmental Score: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Affected API Connect
|
Affected Versions
—|—
IBM API Connect| 5.0.0.0-5.0.7.1
IBM API Management| 4.0.0.0-4.0.4.5
Product
|
VRMF
|
APAR
|
Remediation / First Fix
—|—|—|—
IBM API Connect | 5.0.7.1| LI79690| APIConnect_Management
https://www-945.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7EWebSphere&product=ibm/WebSphere/IBM+API+Connect&release=5.0.7.0&platform=All&function=all
IBM API Connect| 5.0.6.3| LI79690| APIConnect_Management
https://www-945.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7EWebSphere&product=ibm/WebSphere/IBM+API+Connect&release=5.0.6.2&platform=All&function=all
IBM API Management| 4.0.4.6| LI79690| APIManagement-ManagementAppliance