CVE-2016-3012: IBM API Connect
High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.
IBM API Connect (aka APIConnect) before 5.0.3.0 with NPM before 2.2.8 includes certain internal server credentials in the software package, which might allow remote attackers to bypass intended access restrictions by leveraging knowledge of these credentials.
Affected products
Published 2016-12-01. Last modified 2026-06-17.