CVE-2019-4203 HIGH

CVE-2019-4203

Vendor Ibm
Product API Connect
Published April 15, 2019
Last update September 17, 2024

CVSS base score

8.9/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.0/I:L/C:H/AC:L/UI:R/S:C/A:H/PR:L/AV:N/E:U/RL:O/RC:C

What the vulnerability does

01Description

IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal can be exploited by app developers to download arbitrary files from the host OS and potentially carry out SSRF attacks. IBM X-Force ID: 159124.

Key dates

02Disclosure timeline

April 15, 2019 CVE published
September 17, 2024 Record updated