CVE-2015-0149 Information

Description

The developer portal in IBM API Management 3.0 before 3.0.4.1 does not properly restrict access to the public and private APIs which allows remote authenticated users to obtain sensitive information or modify data via unspecified API calls.

Reference

http://www-01.ibm.com/support/docview.wss?uid=swg1LI78430 http://www-01.ibm.com/support/docview.wss?uid=swg21696693

Share on: