CVE-2018-1778
IBM LoopBack (IBM API Connect 2018.1, 2018.4.1, 5.0.8.0, and 5.0.8.4) could allow an attacker to bypass authentication if the AccessToken Model is exposed over a REST API, it is then possible for anyone to create an AccessToken for any User provided…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.45%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
IBM LoopBack (IBM API Connect 2018.1, 2018.4.1, 5.0.8.0, and 5.0.8.4) could allow an attacker to bypass authentication if the AccessToken Model is exposed over a REST API, it is then possible for anyone to create an AccessToken for any User provided they know the userId and can hence get access to the other user’s data / access to their privileges (if the user happens to be an Admin for example). IBM X-Force ID: 148801.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.45% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- ibm/api connect
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=ibm10733883Patch, Vendor Advisory
- http://www.securityfocus.com/bid/106313Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/148801VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=ibm10733883Patch, Vendor Advisory
- http://www.securityfocus.com/bid/106313Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/148801VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.