CVE-2023-47722: IBM API Connect information disclosure
Published Dec 4, 2023
·Updated
IBM API Connect V10 stores user credentials in browser cache which can be read by a local user.
Other sources
IBM API Connect V10.0.5.3 and V10.0.6.0 stores user credentials in browser cache which can be read by a local user. IBM X-Force ID: 271912.
Affected Software
3 affected components
IBM API Connect<=V10.0.5.3 & v10.0.6.0
IBM API Connect=10.0.5.3
IBM API Connect=10.0.6.0
Event History
Dec 4, 2023
CVE Published
12:00 AM
Dec 9, 2023
CVE Published
via MITRE·02:32 AM
Data Sourced
via MITRE·02:32 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this IBM API Connect information disclosure vulnerability?
The vulnerability ID for this IBM API Connect information disclosure vulnerability is CVE-2023-47722.
2
What is the severity of CVE-2023-47722?
The severity of CVE-2023-47722 is medium with a CVSS score of 6.2.
3
How does IBM API Connect V10.0.5.3 and V10.0.6.0 store user credentials?
IBM API Connect V10.0.5.3 and V10.0.6.0 stores user credentials in browser cache.
4
Who can read the user credentials stored in the browser cache?
The user credentials stored in the browser cache can be read by a local user.
5
What are the affected versions of IBM API Connect?
The affected versions of IBM API Connect are V10.0.5.3 and V10.0.6.0.
6
Is there a fix available for this vulnerability in IBM API Connect?
For information on available fixes, please refer to the IBM support pages.