CVE-2019-4155: IBM API Connect

Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.

IBM API Connect's Developer Portal 2018.1 and 2018.4.1.3 is impacted by a privilege escalation vulnerability when integrated with an OpenID Connect (OIDC) user registry. IBM X-Force ID: 158544.

Affected products

  • IBM API Connect: from 2018.1.0, up to and including 2018.4.1.3

Published 2019-04-08. Last modified 2026-06-17.