IBM API Connect V10 could allow an authenticated user to perform actions that they should not have access to. IBM X-Force ID: 250585.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/6965612 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/250585 | vdb entry vendor advisory |