CVE-2017-1386: IBM API Connect
Medium severity, CVSS 5.9. EPSS: 1.2% chance of exploitation in the next 30 days.
IBM API Connect 5.0.0.0 could allow a user to bypass policy restrictions and create non-compliant passwords which could be intercepted and decrypted using man in the middle techniques. IBM X-Force ID: 127160.
Affected products
- IBM API Connect: version 5.0.0.0 only; version 5.0.0.1 only; version 5.0.1.0 only; version 5.0.2.0 only; version 5.0.3.0 only; version 5.0.4.0 only; …
- IBM API Management: version 4.0.0.0 only; version 4.0.0.1 only; version 4.0.1.0 only; version 4.0.2.0 only; version 4.0.2.1 only; version 4.0.3.0 only; …
Published 2017-07-31. Last modified 2026-06-17.