IBM API Connect's API Manager 2018.4.1.0 through 2018.4.1.12 is vulnerable to privilege escalation. An invitee to an API Provider organization can escalate privileges by manipulating the invitation link. IBM X-Force ID: 185508.
| Software | From | Fixed in |
|---|---|---|
| ibm / api_connect | 2018.4.1.0 | 2018.4.1.12.x |