Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
IBM API Connect 2018.1 through 2018.4.1.7 Developer Portal's user registration page does not disable password autocomplete. An attacker with access to the browser instance and local system credentials can steal the credentials used for registration. IBM X-Force ID: 163453.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM API Connect 信息泄露漏洞
Vulnerability Description
IBM API Connect(APIConnect)是美国IBM公司的一套用于管理API生命周期的集成解决方案。该产品支持创建、运行、管理和保护API和微服务等。 IBM API Connect 2018.1版本至2018.4.1.7版本中存在安全漏洞,该漏洞源于IBM API Connect Developer Portal的用户注册页面没有禁用密码自动填充功能。攻击者可利用该漏洞窃取用于注册的凭证。
CVSS Information
N/A
Vulnerability Type
N/A