IBM / Api Connect
81 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-9074 | IBM API Connect SQL Injection | CRITICAL | 9.8 | Jul 8, 2026 |
| CVE-2026-3144 | IBM API Connect Default Credentials | CRITICAL | 9.8 | Jul 8, 2026 |
| CVE-2025-13915 | Authentication bypass in IBM API Connect | CRITICAL | 9.8 | Dec 26, 2025 |
| CVE-2023-47722 | IBM API Connect information disclosure | MEDIUM | 6.2 | Dec 9, 2023 |
| CVE-2023-28522 | IBM API Connect improper access control | HIGH | 8.8 | May 12, 2023 |
| CVE-2022-34350 | IBM API Connect security bypass | HIGH | 7.5 | Feb 8, 2023 |
| CVE-2021-38997 | IBM API Connect HOST header injection | MEDIUM | 5.4 | Dec 1, 2022 |
| CVE-2021-29772 | IBM API Connect 5.0.0.0 through 5.0.8.11 could allow a user to potentially inject code due to unsanitized user input. IBM X-Force ID: 202774. | CRITICAL | 9.8 | Aug 26, 2021 |
| CVE-2021-29715 | IBM API Connect 5.0.0.0 through 5.0.8.11 could alllow a remote user to obtain sensitive information or conduct denial of serivce attacks due to open ports. IBM… | CRITICAL | 9.1 | Aug 26, 2021 |
| CVE-2020-4706 | IBM API Connect 5.0.0.0 through 5.0.8.10 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a speci… | MEDIUM | 5.4 | Aug 17, 2021 |
| CVE-2020-4707 | IBM API Connect 5.0.0.0 through 5.0.8.11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U… | MEDIUM | 5.4 | Aug 4, 2021 |
| CVE-2021-20440 | IBM API Connect 10.0.0.0, and 2018.4.1.0 through 2018.4.1.13 does not restrict member registration to the intended recepient. An attacker who is a valid user i… | MEDIUM | 4.3 | Mar 15, 2021 |
| CVE-2020-4903 | IBM API Connect V10 and V2018 could allow an attacker who has intercepted a registration invitation link to impersonate the registered user or obtain sensitive… | MEDIUM | 6.5 | Mar 8, 2021 |
| CVE-2020-4695 | IBM API Connect V10 is impacted by insecure communications during database replication. As the data replication happens over insecure communication channels, a… | HIGH | 7.5 | Mar 8, 2021 |
| CVE-2020-4828 | IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to web cache poisoning, caused by improper input validation by modif… | MEDIUM | 6.5 | Feb 4, 2021 |
| CVE-2020-4827 | IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site request forgery which could allow an attacker to execu… | MEDIUM | 4.3 | Feb 4, 2021 |
| CVE-2020-4826 | IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site request forgery which could allow an attacker to execu… | MEDIUM | 4.3 | Feb 4, 2021 |
| CVE-2020-4825 | IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar… | MEDIUM | 5.4 | Feb 4, 2021 |
| CVE-2020-4640 | Certain IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 configurations can result in sensitive information in the URL fragment ide… | MEDIUM | 4.1 | Feb 4, 2021 |
| CVE-2020-4838 | IBM API Connect 5.0.0.0 through 5.0.8.10 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th… | MEDIUM | 5.4 | Jan 12, 2021 |
| CVE-2020-4899 | IBM API Connect 5.0.0.0 through 5.0.8.10 could potentially leak sensitive information or allow for data corruption due to plain text transmission of sensitive… | CRITICAL | 9.1 | Jan 5, 2021 |
| CVE-2020-4638 | IBM API Connect's API Manager 2018.4.1.0 through 2018.4.1.12 is vulnerable to privilege escalation. An invitee to an API Provider organization can escalate pri… | HIGH | 7.2 | Sep 3, 2020 |
| CVE-2020-4337 | IBM API Connect 2018.4.1.0 through 2018.4.1.12 could allow an attacker to launch phishing attacks by tricking the server to generate user registration emails t… | MEDIUM | 6.5 | Sep 3, 2020 |
| CVE-2020-4452 | IBM API Connect V2018.4.1.0 through 2018.4.1.11 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive inf… | HIGH | 7.5 | Jun 29, 2020 |
| CVE-2020-4251 | IBM API Connect 5.0.0.0 through 5.0.8.8 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI… | MEDIUM | 5.4 | Jun 12, 2020 |
Showing 1 to 25 of 81 CVEs