Impact
IBM API Connect 12.1.0.0 through 12.1.0.3 includes hard‑coded administrative credentials that remain unchanged after installation until a mandatory password change is enforced. An attacker who discovers or guesses these default credentials can authenticate to the management console before any credential policy is applied, granting them unrestricted administrative access to the API platform.
Affected Systems
The vulnerability affects all installations of IBM API Connect releases 12.1.0.0, 12.1.0.1, 12.1.0.2, and 12.1.0.3. Systems running any of these versions that have not yet changed the default administrative username and password are exposed.
Risk and Exploitability
The CVSS score of 8.1 classifies this issue as high severity. Exploitation requires no special tools; an attacker simply needs the preset default credentials and remote connectivity to the administrative interface. The EPSS score of <1% indicates a very low probability of exploitation in the observed landscape, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is remote access to the API Connect management console using the default credentials.
OpenCVE Enrichment