---
cve: "CVE-2018-1774"
severity: "HIGH"
cvss: 8.9
epss: "1.1%"
vendor: "IBM"
kev: false
exploited: false
published: "2018-11-09 01:29:00"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-12T00:01:22+02:00"
---

# CVE-2018-1774

> 8.9 HIGH

## Beschreibung

IBM API Connect 5.0.0.0, 5.0.8.4, 2018.1 and 2018.3.6 is vulnerable to CSV injection via the developer portal and analytics that could contain malicious commands that would be executed once opened by an administrator. IBM X-Force ID: 148692.

## CVSS-Vektor

```
CVSS:3.0/A:L/AC:L/AV:N/C:H/I:H/PR:L/S:C/UI:R/E:U/RC:C/RL:O
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Erforderlich | good |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Gering | warn |

## Referenzen

- <https://www.ibm.com/support/docview.wss?uid=ibm10737867>
- <https://exchange.xforce.ibmcloud.com/vulnerabilities/148692>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2018-1774) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
