CVE-2018-2009

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
11/03/2019
Last modified:
09/10/2019

Description

IBM API Connect v2018.1 and 2018.4.1 is affected by an information disclosure vulnerability in the consumer API. Any registered user can obtain a list of all other users in all other orgs, including email id/names, etc. IBM X-Force ID: 155148.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:api_connect:*:*:*:*:*:*:*:* 2018.1.0 (including) 2018.4.1.0 (including)