#VU74264 Improper access control in API Gateway and API Manager


Published: 2023-03-31

Vulnerability identifier: #VU74264

Vulnerability risk: Low

CVSSv3.1: 2.4 [CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: N/A

CWE-ID: CWE-284

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
API Gateway
Server applications / Application servers
API Manager
Web applications / Other software

Vendor: Axway

Description

The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions when "api.manager.orgadmin.selfservice.enabled" system property is set to "true". An organization administrator can see APIs that belong to other organizations.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

API Gateway: April 2019 - September 2020

API Manager: April 2019 - September 2020


External links
http://docs.axway.com/bundle/axway-open-docs/page/docs/apim_relnotes/20220830_apimgr_relnotes/index.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability