Security Advisory
CVE-2016-3012
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
IBM API Connect (aka APIConnect) before 5.0.3.0 with NPM before 2.2.8 includes certain internal server credentials in the software package, which might allow remote attackers to bypass intended access restrictions by leveraging knowledge of these credentials.