IBM API Connect 5.0.7.0 through 5.0.7.2 is vulnerable to a regular expression attack that could allow an authenticated attacker to use a regex and cause the system to slow or hang. IBM X-Force ID: 131546.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/100831 | third party advisory vdb entry |
http://www.ibm.com/support/docview.wss?uid=swg22008315 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/131546 | vdb entry vendor advisory |