CVE-2018-1858: IBM API Connect

High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.

IBM API Connect 5.0.0.0 through 5.0.8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 151256.

Affected products

  • IBM API Connect: from 5.0.0.0, up to and including 5.0.8.6

Published 2019-06-25. Last modified 2026-06-17.