← Back to CVE List

CVE-2021-20440

Published: 2021-03-15T16:15Z
Last Modified: 2024-11-21T05:46Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
IBM API Connect 10.0.0.0, and 2018.4.1.0 through 2018.4.1.13 does not restrict member registration to the intended recepient. An attacker who is a valid user in the user registry used by API Manager can use a stolen invitation link and register themselves as a member of an API provider organization. IBM X-Force ID: 196536. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt