#VU18278 Server-Side Request Forgery (SSRF) in IBM API Connect - CVE-2019-4203
Published: April 16, 2019
IBM API Connect
IBM Corporation
Description
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input. A remote authenticated attacker can send a specially crafted HTTP request to the Developer Portal and trick the application to initiate requests to arbitrary systems.
Successful exploitation of this vulnerability may allow a remote attacker gain access to download arbitrary files from the affected server.Remediation
Install updates from vendor's website:
http://www.ibm.com/support/fixcentral/swg/quickorder?parent=ibm%7EWebSphere&product=ibm/WebS...