Lucene search

K
ibmIBME87A61D50A30307EC3D9CFA3E29C64D021DB3C5CE0007916D55AAF9BC71C36C3
HistoryMar 20, 2019 - 11:50 p.m.

Security Bulletin: API Connect V2018 is impacted by information leak (CVE-2019-4052)

2019-03-2023:50:01
www.ibm.com
10

0.001 Low

EPSS

Percentile

50.5%

Summary

IBM API Connect has addressed the following vulnerability.

Vulnerability Details

CVEID:CVE-2019-4052
**DESCRIPTION:*IBM API Connect’s apis can be leveraged by unauthenticated users to discover login ids of registered users.
CVSS Base Score: 8.2
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/156544&gt; for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N)

Affected Products and Versions

Affected IBM API Management Affected Versions
IBM API Connect 2018.1-2018.4.1.2

Remediation/Fixes

Affected releases Fixed in VRMF APAR Remediation / First Fix
IBM API Connect V2018.1 - 2018.4.1.2 2018.4.1.3 fixpack LI80652

Addressed in IBM API Connect v2018.4.1.3 fixpack.

Management server is impacted.

Follow this link and find the appropriate form factor for your installation: “management” or apicup* or ICP for 2018.4.1.3.

[http://www.ibm.com/support/fixcentral/swg/quickorder?parent=ibm~WebSphere&amp;product=ibm/WebSphere/IBM+API+Connect&amp;release=2018.4.1.2&amp;platform=All&amp;function=all&amp;source=fc](< http://www.ibm.com/support/fixcentral/swg/quickorder?parent=ibm~WebSphere&product=ibm/WebSphere/IBM+API+Connect&release=2018.4.1.2&platform=All&function=all&source=fc&gt;)

Workarounds and Mitigations

None

0.001 Low

EPSS

Percentile

50.5%

Related for E87A61D50A30307EC3D9CFA3E29C64D021DB3C5CE0007916D55AAF9BC71C36C3