VulnerabilityModified
CVE-2019-4051
Some URIs in IBM API Connect 2018.1 and 2018.4.1.3 disclose system specification information like the machine id, system uuid, filesystem paths, network interface names along with their mac addresses.
MEDIUM 5.3EPSS 1.70%
Does this matter?
Lower severity and a low EPSS score (1.70%). Track it; it rarely justifies an emergency change on its own.
Description
Some URIs in IBM API Connect 2018.1 and 2018.4.1.3 disclose system specification information like the machine id, system uuid, filesystem paths, network interface names along with their mac addresses. An attacker can use this information in targeted attacks. IBM X-Force ID: 156542.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.70% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/api connect
- Source
- psirt@us.ibm.com
References
- http://www.securityfocus.com/bid/107841
- https://exchange.xforce.ibmcloud.com/vulnerabilities/156542VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10879395Vendor Advisory
- http://www.securityfocus.com/bid/107841
- https://exchange.xforce.ibmcloud.com/vulnerabilities/156542VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10879395Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.