CVE-2018-1789: IBM API Connect

Critical severity, CVSS 9.9. EPSS: 1.2% chance of exploitation in the next 30 days.

IBM API Connect v2018.1.0 through v2018.3.4 could allow an attacker to send a specially crafted request to conduct a server side request forgery attack. IBM X-Force ID: 148939.

Affected products

  • IBM API Connect: from 2018.1.0, up to and including 2018.3.4

Published 2018-09-07. Last modified 2026-06-17.