IBM API Connect 5.0.0.0 through 5.0.8.4 allows a user with limited API Administrator level access to give themselves full Administrator level access through the members functionality. IBM X-Force ID: 153914.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Api_connect | Ibm | 5.0.0.0 (including) | 5.0.8.4 (including) |