CVE-2019-4203: IBM API Connect

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal can be exploited by app developers to download arbitrary files from the host OS and potentially carry out SSRF attacks. IBM X-Force ID: 159124.

Affected products

  • IBM API Connect: from 5.0.0.0, up to and including 5.0.8.6

Published 2019-04-15. Last modified 2026-06-17.