IBM App Connect Enterprise information disclosure
CVE-2022-42439

6.8MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
6 February 2023

Summary

IBM App Connect Enterprise 11.0.0.17 through 11.0.0.19 and 12.0.4.0 and 12.0.5.0 contains an unspecified vulnerability in the Discovery Connector nodes which may cause a 3rd party system’s credentials to be exposed to a privileged attacker. IBM X-Force ID: 238211.

Affected Version(s)

App Connect Enterprise 11.0.0.17 < 11.0.0.19

App Connect Enterprise 12.0.4.0 < 12.0.5.0

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.