Access Control Weakness in IBM API Management
CVE-2015-0149
Currently unrated
Summary
The developer portal in IBM API Management prior to version 3.0.4.1 fails to enforce proper access controls on both public and private APIs. This oversight can lead to remote authenticated users gaining unauthorized access to sensitive information or modifying data through undisclosed API calls, posing a significant risk to data integrity and confidentiality.
References
Timeline
Vulnerability published
Vulnerability Reserved