Impact
Based on the description, it is inferred that the vulnerability allows an attacker to manipulate the SQL statements executed by the system, potentially enabling the read, modification, or deletion of application data stored in the database. The CVE description does not specify remote code execution, but the nature of the flaw means an attacker could, if the database permits, alter data or schema that could impact the application’s integrity and confidentiality.
Affected Systems
The affected product is IBM API Connect. Vulnerable releases include 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3. It is inferred that all deployments of these versions are susceptible regardless of other configuration settings, though this is not explicitly stated in the CVE data.
Risk and Exploitability
The CVSS score of 9.1 indicates a high‑severity vulnerability that can be exploited remotely without authentication. Based on the description, it is inferred that the flaw can be triggered by sending crafted input to the publicly exposed password‑reset endpoint, giving the attacker a broad attack surface. The EPSS score of <1% indicates a low estimated probability of exploitation, but coupled with the high severity, the overall risk remains significant. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the injection could potentially lead to data compromise and, where the database permits, full control over application data.
OpenCVE Enrichment