IBM API Connect 2018.1 through 2018.4.1.6 may inadvertently leak sensitive details about internal servers and network via API swagger. IBM X-force ID: 162947.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.ibm.com/support/docview.wss?uid=ibm10960876 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/162947 | vdb entry vendor advisory |