{"api_version":"1","generated_at":"2026-07-23T10:29:49+00:00","cve":"CVE-2018-1712","urls":{"html":"https://cve.report/CVE-2018-1712","api":"https://cve.report/api/cve/CVE-2018-1712.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-1712","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-1712"},"summary":{"title":"CVE-2018-1712","description":"IBM API Connect's Developer Portal 5.0.0.0 through 5.0.8.3 is vulnerable to Server Side Request Forgery. An attacker, using specially crafted input parameters can trick the server into making potentially malicious calls within the trusted network. IBM X-Force ID: 146370.","state":"PUBLIC","assigner":"psirt@us.ibm.com","published_at":"2018-08-16 19:29:00","updated_at":"2019-10-09 23:38:00"},"problem_types":["CWE-352"],"metrics":[],"references":[{"url":"https://www-01.ibm.com/support/docview.wss?uid=ibm10716169","name":"https://www-01.ibm.com/support/docview.wss?uid=ibm10716169","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Security Bulletin: IBM API Connect Developer Portal is vulnerable to Server Side Request Forgery (CVE-2018-1712)","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/146370","name":"ibm-api-cve20181712-ssrf(146370)","refsource":"XF","tags":["VDB Entry","Vendor Advisory"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-1712","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-1712","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"1712","vulnerable":"1","versionEndIncluding":"5.0.8.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"api_connect","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"psirt@us.ibm.com","DATE_PUBLIC":"2018-08-15T00:00:00","ID":"CVE-2018-1712","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"API Connect","version":{"version_data":[{"version_value":"5.0.1.0"},{"version_value":"5.0.0.0"},{"version_value":"5.0.0.1"},{"version_value":"5.0.2.0"},{"version_value":"5.0.5.0"},{"version_value":"5.0.6.0"},{"version_value":"5.0.6.1"},{"version_value":"5.0.6.2"},{"version_value":"5.0.7.0"},{"version_value":"5.0.7.1"},{"version_value":"5.0.3.0"},{"version_value":"5.0.4.0"},{"version_value":"5.0.7.2"},{"version_value":"5.0.6.3"},{"version_value":"5.0.6.4"},{"version_value":"5.0.8.0"},{"version_value":"5.0.8.1"},{"version_value":"5.0.6.5"},{"version_value":"5.0.6.6"},{"version_value":"5.0.8.2"},{"version_value":"5.0.8.3"}]}}]},"vendor_name":"IBM"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"IBM API Connect's Developer Portal 5.0.0.0 through 5.0.8.3 is vulnerable to Server Side Request Forgery. An attacker, using specially crafted input parameters can trick the server into making potentially malicious calls within the trusted network. IBM X-Force ID: 146370."}]},"impact":{"cvssv3":{"BM":{"A":"L","AC":"L","AV":"N","C":"H","I":"L","PR":"N","S":"U","SCORE":"8.600","UI":"N"},"TM":{"E":"U","RC":"C","RL":"O"}}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Obtain Information"}]}]},"references":{"reference_data":[{"name":"ibm-api-cve20181712-ssrf(146370)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/146370"},{"name":"https://www-01.ibm.com/support/docview.wss?uid=ibm10716169","refsource":"CONFIRM","url":"https://www-01.ibm.com/support/docview.wss?uid=ibm10716169"}]}},"nvd":{"publishedDate":"2018-08-16 19:29:00","lastModifiedDate":"2019-10-09 23:38:00","problem_types":["CWE-352"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":9.9,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.3},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:api_connect:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0.0.0","versionEndIncluding":"5.0.8.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"1712","Ordinal":"117236","Title":"CVE-2018-1712","CVE":"CVE-2018-1712","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"1712","Ordinal":"1","NoteData":"IBM API Connect's Developer Portal 5.0.0.0 through 5.0.8.3 is vulnerable to Server Side Request Forgery. An attacker, using specially crafted input parameters can trick the server into making potentially malicious calls within the trusted network. IBM X-Force ID: 146370.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"1712","Ordinal":"2","NoteData":"2018-08-16","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"1712","Ordinal":"3","NoteData":"2018-08-16","Type":"Other","Title":"Modified"}]}}}