ZeroHour

CVE-2018-1712

CVSS 3.0
9.9 critical
EPSS
<1%p52
Published
()
Modified
Description

IBM API Connect's Developer Portal 5.0.0.0 through 5.0.8.3 is vulnerable to Server Side Request Forgery. An attacker, using specially crafted input parameters can trick the server into making potentially malicious calls within the trusted network. IBM X-Force ID: 146370.

Vendors
ibm
Products
api connect
Weakness
CWE-352
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L

In the news

No ingested article mentions this CVE yet.