Phishing Vulnerability in IBM API Connect Product
CVE-2020-4337
6.5MEDIUM
Summary
A vulnerability in IBM API Connect versions 2018.4.1.0 through 2018.4.1.12 may allow attackers to exploit the software by generating fraudulent user registration emails with malicious URLs, potentially leading to phishing attacks. This flaw highlights the importance of securing API communication and validating email contents to prevent misuse.
Affected Version(s)
API Connect 2018.4.1.0
API Connect 2018.4.1.12
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved