IBM Security Bulletin: Weaker than expected security in IBM API Connect (CVE-2017-1386)

IBM API Connect has addressed the following vulnerability which allows the possibility of bypassing password policy.

CVE(s): CVE-2017-1386

Affected product(s) and affected version(s):

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2vb0UBO
X-Force Database: http://ift.tt/2w3efIV

The post IBM Security Bulletin: Weaker than expected security in IBM API Connect (CVE-2017-1386) appeared first on IBM PSIRT Blog.

Affected API ConnectAffected Versions
IBM API Connect5.0.0.0-5.0.7.1
IBM API Management4.0.0.0-4.0.4.5


from IBM Product Security Incident Response Team http://ift.tt/2vaAj7X