CVE-2018-1712: IBM API Connect

Critical severity, CVSS 9.9. EPSS: 0.7% chance of exploitation in the next 30 days.

IBM API Connect's Developer Portal 5.0.0.0 through 5.0.8.3 is vulnerable to Server Side Request Forgery. An attacker, using specially crafted input parameters can trick the server into making potentially malicious calls within the trusted network. IBM X-Force ID: 146370.

Affected products

  • IBM API Connect: from 5.0.0.0, up to and including 5.0.8.3

Published 2018-08-16. Last modified 2026-06-17.