IBM API Connect(APIConnect)是美国IBM公司的一套用于管理API生命周期的集成解决方案。该产品支持创建、运行、管理和保护API和微服务等。 IBM API Connect 中存在跨站脚本漏洞。此漏洞允许用户在Web UI中嵌入任意JavaScript代码,从而改变预期的功能,从而可能导致可信会话中的凭据泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | API Connect | 2018.4.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-4640 | IBM API Connect 信息泄露漏洞 | |
| CVE-2020-4826 | IBM API Connect 跨站请求伪造漏洞 | |
| CVE-2020-4827 | IBM API Connect 跨站请求伪造漏洞 | |
| CVE-2020-4828 | IBM API Connect 输入验证错误漏洞 | |
| CVE-2020-5032 | IBM QRadar SIEM 安全漏洞 |
No comments yet