CVE-2017-1328
 
Severity Score
5.3
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
IBM API Connect 5.0.0.0 - 5.0.6.0 could allow a remote attacker to bypass security restrictions of the api, caused by improper handling of security policy. By crafting a suitable request, an attacker could exploit this vulnerability to bypass security and use the vulnerable API. IBM X-Force ID: 126230.
IBM API Connect 5.0.0.0 - 5.0.6.0 podría permitir que un atacante remoto omita las restricciones de seguridad de la API, provocado por la gestión incorrecta de la política de seguridad. Al manipular una petición adecuada, un atacante podría explotar esta vulnerabilidad para omitir la seguridad y emplear la API vulnerable. IBM X-Force ID: 126230.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2016-11-30 CVE Reserved
- 2017-06-27 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/99267 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.ibm.com/support/docview.wss?uid=swg22003867 | 2019-10-03 |
URL | Date | SRC |
---|---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/126230 | 2019-10-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Api Connect Search vendor "Ibm" for product "Api Connect" | 5.0.0.0 Search vendor "Ibm" for product "Api Connect" and version "5.0.0.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Api Connect Search vendor "Ibm" for product "Api Connect" | 5.0.0.1 Search vendor "Ibm" for product "Api Connect" and version "5.0.0.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Api Connect Search vendor "Ibm" for product "Api Connect" | 5.0.1.0 Search vendor "Ibm" for product "Api Connect" and version "5.0.1.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Api Connect Search vendor "Ibm" for product "Api Connect" | 5.0.2.0 Search vendor "Ibm" for product "Api Connect" and version "5.0.2.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Api Connect Search vendor "Ibm" for product "Api Connect" | 5.0.3.0 Search vendor "Ibm" for product "Api Connect" and version "5.0.3.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Api Connect Search vendor "Ibm" for product "Api Connect" | 5.0.4.0 Search vendor "Ibm" for product "Api Connect" and version "5.0.4.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Api Connect Search vendor "Ibm" for product "Api Connect" | 5.0.5.0 Search vendor "Ibm" for product "Api Connect" and version "5.0.5.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Api Connect Search vendor "Ibm" for product "Api Connect" | 5.0.6.0 Search vendor "Ibm" for product "Api Connect" and version "5.0.6.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Api Connect Search vendor "Ibm" for product "Api Connect" | 5.0.6.1 Search vendor "Ibm" for product "Api Connect" and version "5.0.6.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Api Connect Search vendor "Ibm" for product "Api Connect" | 5.0.6.2 Search vendor "Ibm" for product "Api Connect" and version "5.0.6.2" | - |
Affected
|