Certain IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 configurations can result in sensitive information in the URL fragment identifiers. This information can be cached in the intermediate nodes like proxy servers, cdn, logging platforms, etc. An attacker can make use of this information to perform attacks by impersonating a user. IBM X-Force ID: 185510.
Conclusion & alert: CVE-2020-4640 is rated Low Risk (25.9/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.35%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.08% | 0.35% | +0.27% |
| 2 | 2025-03-17 | 0.04% | 0.08% | +0.03% |
| 3 | 2023-03-07 | — | 0.04% | — |
Full EPSS history (7 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 4.1 | 3.1 | MEDIUM |
|
1.5 | 2.5 | [email protected] |
| 3.4 | 3.0 | LOW |
|
0.9 | 2.5 | [email protected] |
| 3.8 | 2.0 | LOW |
|
4.4 | 4.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| ibm | api_connect | >= 2018.4.1.0, <= 2018.4.1.13 | cpe:2.3:a:ibm:api_connect:*:*:*:*:*:*:*:* |
| ibm | api_connect | 10.0.0.0 | cpe:2.3:a:ibm:api_connect:10.0.0.0:*:*:*:*:*:*:* |
| ibm | api_connect | 10.0.1.0 | cpe:2.3:a:ibm:api_connect:10.0.1.0:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://exchange.xforce.ibmcloud.com/vulnerabilities/185510 | VDB Entry Vendor Advisory |
| https://www.ibm.com/support/pages/node/6410486 | Vendor Advisory |