CVE-2019-4051 MEDIUM

CVE-2019-4051

Vendor Ibm
Product API Connect
Published April 8, 2019
Last update September 16, 2024

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.0/S:U/UI:N/AV:N/A:N/PR:N/I:N/AC:L/C:L/RC:C/E:U/RL:O

What the vulnerability does

01Description

Some URIs in IBM API Connect 2018.1 and 2018.4.1.3 disclose system specification information like the machine id, system uuid, filesystem paths, network interface names along with their mac addresses. An attacker can use this information in targeted attacks. IBM X-Force ID: 156542.

Key dates

02Disclosure timeline

April 8, 2019 CVE published
September 16, 2024 Record updated