CVE Vulnerabilities

CVE-2018-1973

Improper Privilege Management

Published: Dec 20, 2018 | Modified: Oct 09, 2019
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

IBM API Connect 5.0.0.0 through 5.0.8.4 allows a user with limited API Administrator level access to give themselves full Administrator level access through the members functionality. IBM X-Force ID: 153914.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Api_connect Ibm 5.0.0.0 (including) 5.0.8.4 (including)

Potential Mitigations

References