CVE-2018-1784: IBM API Connect

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

IBM API Connect 5.0.0.0 and 5.0.8.4 is affected by a NoSQL Injection in MongoDB connector for the LoopBack framework. IBM X-Force ID: 148807.

Affected products

  • IBM API Connect: from 5.0.0.0, up to and including 5.0.8.4

Published 2018-12-20. Last modified 2026-06-17.