Improper access control in API Gateway and API Manager - #VU74264
Published: March 31, 2023
Vulnerability identifier: #VU74264
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions when "api.manager.orgadmin.selfservice.enabled" system property is set to "true". An organization administrator can see APIs that belong to other organizations.
Affected software
API Gateway
API Manager
API Manager
Remediation
Install updates from vendor's website.
API Gateway - update to August 2022
API Manager - update to August 2022
API Manager - update to August 2022