
CVE-2021-29772
https://notcve.org/view.php?id=CVE-2021-29772
26 Aug 2021 — IBM API Connect 5.0.0.0 through 5.0.8.11 could allow a user to potentially inject code due to unsanitized user input. IBM X-Force ID: 202774. IBM API Connect versiones 5.0.0.0 hasta 5.0.8.11, podría permitir a un usuario inyectar potencialmente código debido a una entrada de usuario no saneada. IBM X-Force ID: 202774. • https://exchange.xforce.ibmcloud.com/vulnerabilities/202774 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2021-29715
https://notcve.org/view.php?id=CVE-2021-29715
26 Aug 2021 — IBM API Connect 5.0.0.0 through 5.0.8.11 could alllow a remote user to obtain sensitive information or conduct denial of serivce attacks due to open ports. IBM X-Force ID: 201018. IBM API Connect versiones 5.0.0.0 hasta 5.0.8.11, podría permitir a un usuario remoto conseguir información confidencial o conducir ataques de denegación de servicio debido a los puertos abiertos. IBM X-Force ID: 201018. • https://exchange.xforce.ibmcloud.com/vulnerabilities/201018 •

CVE-2020-4706
https://notcve.org/view.php?id=CVE-2020-4706
17 Aug 2021 — IBM API Connect 5.0.0.0 through 5.0.8.10 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to inject HTTP HOST header, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 187194. IBM API Connect versiones 5.0.0.0 hasta 5.0.8.10, es vulnerable a... • https://exchange.xforce.ibmcloud.com/vulnerabilities/187194 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2020-4707
https://notcve.org/view.php?id=CVE-2020-4707
04 Aug 2021 — IBM API Connect 5.0.0.0 through 5.0.8.11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 187370. IBM API Connect versiones 5.0.0.0 hasta 5.0.8.11, es vulnerable a un ataque de tipo cross-site scripting. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrario en la interfaz de usuario web, ... • https://exchange.xforce.ibmcloud.com/vulnerabilities/187370 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2020-4838
https://notcve.org/view.php?id=CVE-2020-4838
12 Jan 2021 — IBM API Connect 5.0.0.0 through 5.0.8.10 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190036. IBM API Connect versiones 5.0.0.0 hasta 5.0.8.10, es vulnerable a un ataque de tipo cross-site scripting almacenado. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrario en la In... • https://exchange.xforce.ibmcloud.com/vulnerabilities/190036 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2020-4899
https://notcve.org/view.php?id=CVE-2020-4899
05 Jan 2021 — IBM API Connect 5.0.0.0 through 5.0.8.10 could potentially leak sensitive information or allow for data corruption due to plain text transmission of sensitive information across the network. IBM X-Force ID: 190990. IBM API Connect versiones 5.0.0.0 hasta 5.0.8.10, podría potencialmente filtrar información confidencial o permitir una corrupción de datos debido a una transmisión en texto plano de información confidencial a través de la red. IBM X-Force ID: 190990 • https://exchange.xforce.ibmcloud.com/vulnerabilities/190990 • CWE-319: Cleartext Transmission of Sensitive Information •

CVE-2020-4251
https://notcve.org/view.php?id=CVE-2020-4251
12 Jun 2020 — IBM API Connect 5.0.0.0 through 5.0.8.8 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 175489. IBM API Connect versiones 5.0.0.0 hasta 5.0.8.8, es vulnerable a un ataque de tipo cross-site scripting. Esta vulnerabilidad permite a un usuario insertar código JavaScript arbitrario en la Interfaz de Usuario Web, ... • https://exchange.xforce.ibmcloud.com/vulnerabilities/175489 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2019-4553
https://notcve.org/view.php?id=CVE-2019-4553
24 Mar 2020 — IBM API Connect V5.0.0.0 through 5.0.8.7iFix3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 165958. IBM API Connect versiones V5.0.0.0 hasta 5.0.8.7iFix3, utiliza algoritmos criptográficos más débiles de lo esperado que podrían permitir a un atacante descifrar información altamente confidencial. ID de IBM X-Force: 165958. • https://exchange.xforce.ibmcloud.com/vulnerabilities/165958 • CWE-327: Use of a Broken or Risky Cryptographic Algorithm •

CVE-2019-4600
https://notcve.org/view.php?id=CVE-2019-4600
28 Oct 2019 — IBM API Connect version V5.0.0.0 through 5.0.8.7 could reveal sensitive information to an attacker using a specially crafted HTTP request. IBM X-Force ID: 167883. IBM API Connect versión V5.0.0.0 hasta 5.0.8.7, podría revelar información confidencial a un atacante usando una petición HTTP especialmente diseñada. ID de IBM X-Force: 167883. • https://exchange.xforce.ibmcloud.com/vulnerabilities/167883 •

CVE-2019-4460
https://notcve.org/view.php?id=CVE-2019-4460
20 Aug 2019 — IBM API Connect 5.0.0.0 through 5.0.8.6 developer portal could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 163681. El portal para desarrolladores de IBM API Connect 5.0.0.0 a 5.0.8.6 podría permitir que un atacante remoto atraviese directorios en el sistema. Un atacante podría enviar una solicitud de URL especialmente diseñada que contenga sec... • https://exchange.xforce.ibmcloud.com/vulnerabilities/163681 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •