Apiman is a modestly represented API management and governance platform with a narrow product focus, positioned as middleware for controlling and securing API access across service-oriented architectures. Its vulnerability exposure centers on authorization and privilege-management issues—including improper privilege controls, incorrect default permissions, and missing authorization checks—that reflect the access-control demands of an identity and policy enforcement layer. Current severity, exploitation activity, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Apiman over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-47551MEDIUM Apiman 1.5.7 through 2.2.3.Final has insufficient checks for read permissions within the Apiman Manager REST API. The root cause of the issue is the Apiman project's accidental acc | Dec 20, 2022 | 6.5 | 22 | NO | NO |
Apiman is a flexible and open source API Management platform. Due to a missing permissions check, an attacker with an authenticated Apiman Manager account may be able to gain acces | Mar 27, 2023 | 3.1 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Apiman.
Media articles that mention a CVE ID that affects a product developed by Apiman — matched by CVE ID, not by vendor name.