Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-0149


The developer portal in IBM API Management 3.0 before 3.0.4.1 does not properly restrict access to the public and private APIs, which allows remote authenticated users to obtain sensitive information or modify data via unspecified API calls.


Published

2015-03-18T10:59:06.963

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 5.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.0

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm api_management 3.0.0.0 Yes
Application ibm api_management 3.0.2.0 Yes
Application ibm api_management 3.0.2.1 Yes
Application ibm api_management 3.0.3.0 Yes
Application ibm api_management 3.0.4.0 Yes

References