Api Connect

Vendor:

First CVE: Dec 1, 2016 · Active for 9 years

81
Total CVEs
More Total CVEs than 99% of tracked products
8.1
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 34% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Api Connect over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 1, 2016
9 years ago
Most Recent CVE
Jul 8, 2026
16 days ago

CVE Severity & Scoring

Api Connect81 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local3 (3.7%)
Network76 (93.8%)
Unknown0 (0.0%)
Physical1 (1.2%)
Adjacent Network1 (1.2%)
Attack Complexity
Low77 (95.1%)
High4 (4.9%)
Unknown0 (0.0%)
User Interaction
None65 (80.2%)
Unknown0 (0.0%)
Required16 (19.8%)
Privileges Required
Low24 (29.6%)
High6 (7.4%)
None51 (63.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (81 CVEs).

81 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.
Dec 26, 20259.842NONO
IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.
Jul 8, 20269.840NONO
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credent
Jul 8, 20269.839NONO
IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal is vulnerable to command injection. An attacker with a specially crafted request can run arbitrary code on the server and gain
Apr 15, 201910.032NONO
IBM API Connect's Developer Portal 2018.1 and 2018.4.1.3 is impacted by a privilege escalation vulnerability when integrated with an OpenID Connect (OIDC) user registry. IBM X-Forc
Apr 8, 20199.832NONO
IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal can be exploited by app developers to download arbitrary files from the host OS and potentially carry out SSRF attacks. IBM X-F
Apr 15, 20199.831NONO
API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak. Authorization tokens in some URLs can result in the tokens being written to log files. IBM X-Force ID: 1556
Feb 7, 20199.831NONO
IBM API Connect 5.0.0.0 and 5.0.8.4 is affected by a NoSQL Injection in MongoDB connector for the LoopBack framework. IBM X-Force ID: 148807.
Dec 20, 20189.831NONO
IBM API Connect v2018.1.0 through v2018.3.4 could allow an attacker to send a specially crafted request to conduct a server side request forgery attack. IBM X-Force ID: 148939.
Sep 7, 20189.931NONO
IBM API Connect Developer Portal 5.0.0.0 through 5.0.8.2 could allow an unauthenticated attacker to execute system commands using specially crafted HTTP requests. IBM X-Force ID: 1
Apr 4, 20189.831NONO

Exploit Exposure

Signals from CVEs in this product scope (81 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (81 CVEs).

Media Mentions

Signals from CVEs in this product scope (81 CVEs).

Top CNAs Publishing CVEs For Api Connect

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.0.8.214.31.0%00
5.0.8.134.70.8%00
5.0.8.035.01.3%00
5.0.7.255.30.9%00
5.0.7.165.71.1%00
5.0.7.086.01.3%00
5.0.6.425.20.9%00
5.0.6.325.20.9%00
5.0.6.266.21.5%00
5.0.6.166.21.5%00
5.0.6.076.41.5%00
5.0.5.066.21.5%00
5.0.4.066.21.5%00
5.0.3.066.21.5%00
5.0.2.066.21.5%00
5.0.1.066.21.5%00
5.0.0.166.21.5%00
5.0.0.066.21.5%00
2018.4.1.717.50.8%00
10.0.6.015.50.2%00