Vulnerability Description
IBM API Connect 5.0.0.0, 5.0.8.4, 2018.1 and 2018.3.6 is vulnerable to CSV injection via the developer portal and analytics that could contain malicious commands that would be executed once opened by an administrator. IBM X-Force ID: 148692.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Api Connect | >= 5.0.0.0, <= 5.0.8.4 |
Related Weaknesses (CWE)
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/148692VDB EntryVendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10737867Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/148692VDB EntryVendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10737867Vendor Advisory
FAQ
What is CVE-2018-1774?
CVE-2018-1774 is a vulnerability with a CVSS score of 8.9 (HIGH). IBM API Connect 5.0.0.0, 5.0.8.4, 2018.1 and 2018.3.6 is vulnerable to CSV injection via the developer portal and analytics that could contain malicious commands that would be executed once opened by ...
How severe is CVE-2018-1774?
CVE-2018-1774 has been rated HIGH with a CVSS base score of 8.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-1774?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Api Connect.