IBM App Connect Enterprise information disclosure

CVE-2024-31894
4.3MEDIUM

Key Information

Vendor
IBM
Status
App Connect Enterprise
Vendor
Published:
22 May 2024

Summary

IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user information using an expired access token. IBM X-Force ID: 288175.

Affected Version(s)

App Connect Enterprise <= 12.0.12.1

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
LOW
Integrity:
NONE
Availability:
NONE
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
UNCHANGED

Timeline

  • Risk change from: null to: 4.3 - (MEDIUM)

  • Vulnerability published.

Collectors

NVD DatabaseMitre Database
.