« Back to list

CVE-2018-1599

Status: ModifiedMedium (5.4)—

IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 143744.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2018-1599",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "psirt@us.ibm.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@us.ibm.com",
      "affectedData": [
        {
          "vendor": "IBM",
          "product": "API Connect",
          "versions": [
            {
              "status": "affected",
              "version": "5.0.1.0"
            },
            {
              "status": "affected",
              "version": "5.0.0.0"
            },
            {
              "status": "affected",
              "version": "5.0.2.0"
            },
            {
              "status": "affected",
              "version": "5.0.5.0"
            },
            {
              "status": "affected",
              "version": "5.0.6.0"
            },
            {
              "status": "affected",
              "version": "5.0.6.1"
            },
            {
              "status": "affected",
              "version": "5.0.6.2"
            },
            {
              "status": "affected",
              "version": "5.0.7.0"
            },
            {
              "status": "affected",
              "version": "5.0.7.1"
            },
            {
              "status": "affected",
              "version": "5.0.3.0"
            },
            {
              "status": "affected",
              "version": "5.0.4.0"
            },
            {
              "status": "affected",
              "version": "5.0.7.2"
            },
            {
              "status": "affected",
              "version": "5.0.6.3"
            },
            {
              "status": "affected",
              "version": "5.0.6.4"
            },
            {
              "status": "affected",
              "version": "5.0.8.0"
            },
            {
              "status": "affected",
              "version": "5.0.8.1"
            },
            {
              "status": "affected",
              "version": "5.0.6.5"
            },
            {
              "status": "affected",
              "version": "5.0.6.6"
            },
            {
              "status": "affected",
              "version": "5.0.8.2"
            },
            {
              "status": "affected",
              "version": "5.0.8.3"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-08-22T11:29:00.230",
  "references": [
    {
      "url": "http://www.ibm.com/support/docview.wss?uid=swg22016672",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/143744",
      "tags": [
        "VDB Entry",
        "Vendor Advisory"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "http://www.ibm.com/support/docview.wss?uid=swg22016672",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/143744",
      "tags": [
        "VDB Entry",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 143744."
    },
    {
      "lang": "es",
      "value": "IBM API Connect desde la versión 5.0.0.0 hasta la 5.0.8.3 podría permitir que un atacante remoto secuestre la acción de clicado de la víctima. Al persuadir a una víctima para que visite un sitio web malicioso, un atacante remoto podría explotar esta vulnerabilidad para secuestrar las acciones de clicado de la víctima y, probablemente, lanzar más ataques contra la víctima. IBM X-Force ID: 143744."
    }
  ],
  "lastModified": "2026-06-17T01:51:28.050",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ibm:api_connect:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6C687196-D8CA-4070-8598-557588E47663",
              "versionEndIncluding": "5.0.8.3",
              "versionStartIncluding": "5.0.0.0"
            },
            {
              "criteria": "cpe:2.3:a:ibm:api_connect:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "26DD58A1-6046-406D-8FC4-4C0769A72DA1",
              "versionEndIncluding": "2018.3.4",
              "versionStartIncluding": "2018.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@us.ibm.com"
}