cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2023-47722,https://securityvulnerability.io/vulnerability/CVE-2023-47722,IBM API Connect information disclosure,IBM API Connect V10.0.5.3 and V10.0.6.0 stores user credentials in browser cache which can be read by a local user. IBM X-Force ID: 271912.,IBM,API Connect,6.2,MEDIUM,0.0004199999966658652,false,,false,false,false,,,false,false,,2023-12-09T03:15:00.000Z,0 CVE-2023-28522,https://securityvulnerability.io/vulnerability/CVE-2023-28522,IBM API Connect improper access control,"IBM API Connect V10 experiences a significant access control vulnerability that could enable an authenticated user to engage in unauthorized actions, thus compromising data integrity and application security. This vulnerability highlights the importance of proper access controls in safeguarding sensitive APIs. Organizations utilizing this version of IBM's API management solution should review their configurations to mitigate potential risks associated with unauthorized access.",IBM,Api Connect,4.3,MEDIUM,0.0008500000112690032,false,,false,false,false,,,false,false,,2023-05-12T02:15:00.000Z,0 CVE-2022-34350,https://securityvulnerability.io/vulnerability/CVE-2022-34350,IBM API Connect security bypass,"IBM API Connect 10.0.0.0 through 10.0.5.0, 10.0.1.0 through 10.0.1.7, and 2018.4.1.0 through 2018.4.1.20 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By submitting suitable payloads, an attacker can cause the application server to attack other systems that it can interact with. IBM X-Force ID: 230264.",IBM,Api Connect,5.3,MEDIUM,0.001069999998435378,false,,false,false,false,,,false,false,,2023-02-08T19:12:31.221Z,0 CVE-2021-38997,https://securityvulnerability.io/vulnerability/CVE-2021-38997,IBM API Connect HOST header injection,"IBM API Connect V10.0.0.0 through V10.0.5.0, V10.0.1.0 through V10.0.1.7, and V2018.4.1.0 through 2018.4.1.19 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 213212.",IBM,Api Connect,5.4,MEDIUM,0.0005000000237487257,false,,false,false,false,,,false,false,,2022-12-12T09:15:00.000Z,0 CVE-2021-29772,https://securityvulnerability.io/vulnerability/CVE-2021-29772,Code Injection Vulnerability in IBM API Connect Affects Multiple Versions,"IBM API Connect versions 5.0.0.0 through 5.0.8.11 contain a vulnerability that allows attackers to potentially exploit unsanitized user input. This could lead to unauthorized code execution, compromising the security of applications utilizing the affected product. Proper input validation should be implemented to mitigate these risks.",IBM,Api Connect,5.6,MEDIUM,0.00215999991632998,false,,false,false,false,,,false,false,,2021-08-26T20:15:00.000Z,0 CVE-2021-29715,https://securityvulnerability.io/vulnerability/CVE-2021-29715,Denial of Service Vulnerability in IBM API Connect,"IBM API Connect versions 5.0.0.0 through 5.0.8.11 contain a vulnerability that allows unauthorized remote users to gain access to sensitive information or initiate denial of service attacks. This issue arises from improperly secured open ports within the application, potentially exposing critical data and affecting service availability.",IBM,Api Connect,6.5,MEDIUM,0.003060000017285347,false,,false,false,false,,,false,false,,2021-08-26T20:15:00.000Z,0 CVE-2020-4706,https://securityvulnerability.io/vulnerability/CVE-2020-4706,HTTP Header Injection Vulnerability in IBM API Connect,"IBM API Connect versions 5.0.0.0 through 5.0.8.10 are susceptible to an HTTP header injection vulnerability due to insufficient validation of user input in the HOST headers. When an attacker sends a crafted HTTP request, they could manipulate the HOST header, thereby enabling a range of potential attacks, including cross-site scripting, cache poisoning, and session hijacking, exploiting the security weakness of the affected system.",IBM,Api Connect,5.4,MEDIUM,0.0006099999882280827,false,,false,false,false,,,false,false,,2021-08-17T14:15:00.000Z,0 CVE-2020-4707,https://securityvulnerability.io/vulnerability/CVE-2020-4707,Cross-Site Scripting in IBM API Connect,IBM API Connect versions from 5.0.0.0 to 5.0.8.11 are susceptible to a cross-site scripting vulnerability that may permit users to inject arbitrary JavaScript code through the Web UI. This security flaw can alter the intended functionalities of the application and puts user credentials at risk of exposure during a trusted session. Organizations using affected versions should apply patches or mitigations to safeguard against potential exploitation.,IBM,Api Connect,5.4,MEDIUM,0.0005000000237487257,false,,false,false,false,,,false,false,,2021-08-04T14:15:00.000Z,0 CVE-2021-20440,https://securityvulnerability.io/vulnerability/CVE-2021-20440,,"IBM API Connect 10.0.0.0, and 2018.4.1.0 through 2018.4.1.13 does not restrict member registration to the intended recepient. An attacker who is a valid user in the user registry used by API Manager can use a stolen invitation link and register themselves as a member of an API provider organization. IBM X-Force ID: 196536.",IBM,Api Connect,6.4,MEDIUM,0.0005000000237487257,false,,false,false,false,,,false,false,,2021-03-15T16:15:00.000Z,0 CVE-2020-4695,https://securityvulnerability.io/vulnerability/CVE-2020-4695,,"IBM API Connect V10 is impacted by insecure communications during database replication. As the data replication happens over insecure communication channels, an attacker can view unencrypted data leading to a loss of confidentiality.",IBM,Api Connect,5.9,MEDIUM,0.0010100000072270632,false,,false,false,false,,,false,false,,2021-03-08T18:15:00.000Z,0 CVE-2020-4903,https://securityvulnerability.io/vulnerability/CVE-2020-4903,,IBM API Connect V10 and V2018 could allow an attacker who has intercepted a registration invitation link to impersonate the registered user or obtain sensitive information. IBM X-Force ID: 191105.,IBM,Api Connect,4.8,MEDIUM,0.0006399999838322401,false,,false,false,false,,,false,false,,2021-03-08T18:15:00.000Z,0 CVE-2020-4825,https://securityvulnerability.io/vulnerability/CVE-2020-4825,,IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 189839.,IBM,Api Connect,5.4,MEDIUM,0.0005000000237487257,false,,false,false,false,,,false,false,,2021-02-04T17:15:00.000Z,0 CVE-2020-4828,https://securityvulnerability.io/vulnerability/CVE-2020-4828,,"IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to web cache poisoning, caused by improper input validation by modifying HTTP request headers. IBM X-Force ID: 189842.",IBM,Api Connect,6.5,MEDIUM,0.0006399999838322401,false,,false,false,false,,,false,false,,2021-02-04T17:15:00.000Z,0 CVE-2020-4827,https://securityvulnerability.io/vulnerability/CVE-2020-4827,,IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 189841.,IBM,Api Connect,4.3,MEDIUM,0.0005499999970197678,false,,false,false,false,,,false,false,,2021-02-04T17:15:00.000Z,0 CVE-2020-4640,https://securityvulnerability.io/vulnerability/CVE-2020-4640,,"Certain IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 configurations can result in sensitive information in the URL fragment identifiers. This information can be cached in the intermediate nodes like proxy servers, cdn, logging platforms, etc. An attacker can make use of this information to perform attacks by impersonating a user. IBM X-Force ID: 185510.",IBM,Api Connect,3.4,LOW,0.0004400000034365803,false,,false,false,false,,,false,false,,2021-02-04T17:15:00.000Z,0 CVE-2020-4826,https://securityvulnerability.io/vulnerability/CVE-2020-4826,,IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 189840.,IBM,Api Connect,4.3,MEDIUM,0.0005499999970197678,false,,false,false,false,,,false,false,,2021-02-04T17:15:00.000Z,0 CVE-2020-4838,https://securityvulnerability.io/vulnerability/CVE-2020-4838,,IBM API Connect 5.0.0.0 through 5.0.8.10 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190036.,IBM,Api Connect,6.4,MEDIUM,0.0005000000237487257,false,,false,false,false,,,false,false,,2021-01-12T15:15:00.000Z,0 CVE-2020-4899,https://securityvulnerability.io/vulnerability/CVE-2020-4899,,IBM API Connect 5.0.0.0 through 5.0.8.10 could potentially leak sensitive information or allow for data corruption due to plain text transmission of sensitive information across the network. IBM X-Force ID: 190990.,IBM,Api Connect,7.4,HIGH,0.001069999998435378,false,,false,false,false,,,false,false,,2021-01-05T15:15:00.000Z,0 CVE-2020-4337,https://securityvulnerability.io/vulnerability/CVE-2020-4337,,IBM API Connect 2018.4.1.0 through 2018.4.1.12 could allow an attacker to launch phishing attacks by tricking the server to generate user registration emails that contain malicious URLs. IBM X-Force ID: 177933.,IBM,Api Connect,6.5,MEDIUM,0.0007699999841861427,false,,false,false,false,,,false,false,,2020-09-03T14:15:00.000Z,0 CVE-2020-4638,https://securityvulnerability.io/vulnerability/CVE-2020-4638,,IBM API Connect's API Manager 2018.4.1.0 through 2018.4.1.12 is vulnerable to privilege escalation. An invitee to an API Provider organization can escalate privileges by manipulating the invitation link. IBM X-Force ID: 185508.,IBM,Api Connect,7.2,HIGH,0.0009200000204145908,false,,false,false,false,,,false,false,,2020-09-03T14:15:00.000Z,0 CVE-2020-4452,https://securityvulnerability.io/vulnerability/CVE-2020-4452,,IBM API Connect V2018.4.1.0 through 2018.4.1.11 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 181324.,IBM,Api Connect,5.9,MEDIUM,0.001069999998435378,false,,false,false,false,,,false,false,,2020-06-29T14:15:00.000Z,0 CVE-2020-4251,https://securityvulnerability.io/vulnerability/CVE-2020-4251,,IBM API Connect 5.0.0.0 through 5.0.8.8 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 175489.,IBM,Api Connect,5.4,MEDIUM,0.0005000000237487257,false,,false,false,false,,,false,false,,2020-06-12T13:15:00.000Z,0 CVE-2020-4195,https://securityvulnerability.io/vulnerability/CVE-2020-4195,,"IBM API Connect V2018.4.1.0 through 2018.4.1.10 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 174859.",IBM,Api Connect,5.4,MEDIUM,0.0006500000017695129,false,,false,false,false,,,false,false,,2020-05-12T14:15:00.000Z,0 CVE-2020-4346,https://securityvulnerability.io/vulnerability/CVE-2020-4346,,IBM API Connect's V2018.4.1.0 through 2018.4.1.10 management server has an unsecured api which can be exploited by an unauthenticated attacker to obtain sensitive information. IBM X-Force ID: 178322.,IBM,Api Connect,5.3,MEDIUM,0.0006399999838322401,false,,false,false,false,,,false,false,,2020-05-12T14:15:00.000Z,0 CVE-2019-4553,https://securityvulnerability.io/vulnerability/CVE-2019-4553,,IBM API Connect V5.0.0.0 through 5.0.8.7iFix3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 165958.,IBM,Api Connect,5.9,MEDIUM,0.001069999998435378,false,,false,false,false,,,false,false,,2020-03-24T16:15:00.000Z,0