IBM API Connect 2018.1 up to and including 2018.4.1.7 Developer Portal's user registration page does not disable password autocomplete. An attacker with access to the browser instance and local system credentials can steal the credentials used for registration. IBM X-Force ID: 163453.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ibm api connect |