Authentication bypass in IBM API Connect - CVE-2018-1778
Published: December 26, 2018
IBM API Connect
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass authenticated on the target system.
The vulnerability exists due to an error if the AccessToken Model is exposed over a REST API. A remote attacker can bypass authentication to create an AccessToken for any User provided they know the userID and hence get access to the other users data / access to their privileges (if the user happens to be an Admin for example).