Privilege Escalation in IBM API Connect's API Manager
CVE-2020-4638
7.2HIGH
Summary
IBM API Connect's API Manager versions 2018.4.1.0 through 2018.4.1.12 are susceptible to a vulnerability that allows an invitee to an API Provider organization to escalate their privileges by manipulating the invitation link. This flaw can potentially lead to unauthorized actions and heightened access within the API Manager, raising significant security concerns for organizations utilizing this software.
Affected Version(s)
API Connect 2018.4.1.0
API Connect 2018.4.12
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved