Security researchers at Binary Security have uncovered critical vulnerabilities in Microsoft’s Azure API Management (APIM) service that could allow attackers with basic Reader permissions to gain complete administrative control of the service.
The most severe vulnerability involves exploiting legacy API versions to obtain administrative access tokens.
https://cybersecuritynews.com/azure-api ... abilities/