![](/assets/img/cve_300x82_sin_bg.png)
CVE-2018-1778
https://notcve.org/view.php?id=CVE-2018-1778
20 Dec 2018 — IBM LoopBack (IBM API Connect 2018.1, 2018.4.1, 5.0.8.0, and 5.0.8.4) could allow an attacker to bypass authentication if the AccessToken Model is exposed over a REST API, it is then possible for anyone to create an AccessToken for any User provided they know the userId and can hence get access to the other userâÂÂs data / access to their privileges (if the user happens to be an Admin for example). IBM X-Force ID: 148801. IBM LoopBack (IBM API Connect 2018.1, 2018.4.1, 5.0.8... • http://www.ibm.com/support/docview.wss?uid=ibm10733883 • CWE-287: Improper Authentication •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2018-1774
https://notcve.org/view.php?id=CVE-2018-1774
09 Nov 2018 — IBM API Connect 5.0.0.0, 5.0.8.4, 2018.1 and 2018.3.6 is vulnerable to CSV injection via the developer portal and analytics that could contain malicious commands that would be executed once opened by an administrator. IBM X-Force ID: 148692. IBM API Connect 5.0.0.0, 5.0.8.4, 2018.1 y 2018.3.6 es vulnerable a inyección CSV mediante el portal y las analíticas de desarrollo que podría contener comandos maliciosos que se ejecutarían una vez que sean abiertos por un administrador. IBM X-Force ID: 148692. • https://exchange.xforce.ibmcloud.com/vulnerabilities/148692 • CWE-1236: Improper Neutralization of Formula Elements in a CSV File •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2018-1599
https://notcve.org/view.php?id=CVE-2018-1599
22 Aug 2018 — IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 143744. IBM API Connect desde la versión 5.0.0.0 hasta la 5.0.8.3 podría permitir que un atacante remoto secuestre la acción de clicado de la víctima. Al persuadir a una víctima para ... • http://www.ibm.com/support/docview.wss?uid=swg22016672 • CWE-20: Improper Input Validation •