VulnerabilityModified
CVE-2017-1555
IBM API Connect 5.0.0.0 through 5.0.7.2 could allow an authenticated user to generate an API token when not subscribed to the application plan.
MEDIUM 4.3EPSS 0.91%
Does this matter?
Lower severity and a low EPSS score (0.91%). Track it; it rarely justifies an emergency change on its own.
Description
IBM API Connect 5.0.0.0 through 5.0.7.2 could allow an authenticated user to generate an API token when not subscribed to the application plan. IBM X-Force ID: 131545.
- CVSS 3.0
- 4.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.91% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- ibm/api connect
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=swg22008588Patch, Vendor Advisory
- http://www.securityfocus.com/bid/100973Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/131545VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22008588Patch, Vendor Advisory
- http://www.securityfocus.com/bid/100973Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/131545VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.