CVE-2023-28522: IBM API Connect

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

IBM API Connect V10 could allow an authenticated user to perform actions that they should not have access to. IBM X-Force ID: 250585.

Affected products

  • IBM API Connect: from 10.0.0.0, before 10.0.1.11 (fixed in 10.0.1.11); from 10.0.2.0, before 10.0.5.2 (fixed in 10.0.5.2)

Published 2023-05-12. Last modified 2026-06-17.