IBM API Connect 5.0.0.0-5.0.8.3 Developer Portal does not enforce Two Factor Authentication (TFA) while resetting a user password but enforces it for all other login scenarios. IBM X-Force ID: 144483.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://www.ibm.com/support/docview.wss?uid=ibm10718415 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/144483 | vdb entry vendor advisory |