VulnerabilityModified
CVE-2018-1991
IBM API Connect 5.0.0.0, and 5.0.8.6 could could return sensitive information that could provide critical information as to the underlying software stack in CMC UI headers.
LOW 2.7EPSS 0.96%
Does this matter?
Lower severity and a low EPSS score (0.96%). Track it; it rarely justifies an emergency change on its own.
Description
IBM API Connect 5.0.0.0, and 5.0.8.6 could could return sensitive information that could provide critical information as to the underlying software stack in CMC UI headers. IBM X-Force ID: 154284.
- CVSS 3.0
- 2.7 LOWCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.96% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/api connect
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/154284VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10871970Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/154284VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10871970Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.