IBM App Connect Enterprise denial of service
CVE-2024-22317
9.1CRITICAL
Summary
IBM App Connect Enterprise versions 11.0.0.1 through 11.0.0.24 and 12.0.1.0 through 12.0.11.0 have a vulnerability that exposes the product to remote attacks due to improper handling of excessive authentication attempts. This vulnerability can potentially lead to the unauthorized disclosure of sensitive information or denial of service, posing significant security risks for organizations utilizing these versions. Organizations are advised to apply relevant security updates to mitigate these vulnerabilities and enhance the protection of their systems.
Affected Version(s)
App Connect Enterprise 11.0.0.1 <= 11.0.0.24
App Connect Enterprise 12.0.1.0 <= 12.0.11.0
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved