Improper access control in API Gateway and API Manager - #VU74264

 

Improper access control in API Gateway and API Manager - #VU74264

Published: March 31, 2023


Vulnerability identifier: #VU74264
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions when "api.manager.orgadmin.selfservice.enabled" system property is set to "true". An organization administrator can see APIs that belong to other organizations.


Affected software

API Gateway
API Manager

Remediation

Install updates from vendor's website.

API Gateway - update to August 2022
API Manager - update to August 2022

External References

Related Security Bulletins