Lucene search

K
ibmIBME442D2C9EF94F0F94EC25BE0D3521AE21BEF93CC1A74406D1ACC4EC70792001B
HistoryJun 11, 2020 - 6:07 p.m.

Security Bulletin: IBM API Connect V5 is impacted by an Open Redirect vulnerability in Drupal core(CVE-2020-13662)

2020-06-1118:07:22
www.ibm.com
9

0.001 Low

EPSS

Percentile

34.0%

Summary

IBM API Connect has addressed the following vulnerability.

Vulnerability Details

CVEID:CVE-2020-13662
**DESCRIPTION:**Drupal Core could allow a remote attacker to conduct phishing attacks, caused by insufficient validation of the destination query parameter in the drupal_goto() function. By persuading a victim to click on a specially crafted link, an attacker could exploit this vulnerability to redirect a victim to arbitrary Web sites.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/182278 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
API Connect IBM API Connect V5.0.0.0-5.0.8.8

Remediation/Fixes

Affected Product Addressed in VRMF APAR Remediation/First Fix

IBM API Connect

V5.0.0.0-5.0.8.8

| 5.0.8.8 iFix published on or after June 8, 2020. | LI81520 |

Addressed in IBM API Connect 5.0.8.8 iFix published on or after June 8, 2020.

Developer Portal is impacted.

Follow this link and find the “Portal” package.

http://www.ibm.com/support/fixcentral/swg/quickorder

Workarounds and Mitigations

None

0.001 Low

EPSS

Percentile

34.0%