CVE-2024-22356: IBM App Connect Enterprise and IBM Integration Bus for z/OS information disclosure
IBM App Connect Enterprise 11.0.0.1 through 11.0.0.23, 12.0.1.0 through 12.0.9.0 and IBM Integration Bus for z/OS 10.1 through 10.1.0.2store potentially sensitive information in log or trace files that could be read by a privileged user. IBM X-Force ID: 280893.
Other sources
IBM App Connect Enterprise and IBM Integration Bus for z/OS store potentially sensitive information in log or trace files that could be read by a privileged user.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22356?
CVE-2024-22356 has been classified with moderate severity due to potential exposure of sensitive information in log or trace files.
How can I mitigate CVE-2024-22356?
To mitigate CVE-2024-22356, apply the appropriate patches provided by IBM for the affected versions of App Connect Enterprise and Integration Bus.
Which versions are affected by CVE-2024-22356?
CVE-2024-22356 affects IBM App Connect Enterprise versions 11.0.0.1 to 11.0.0.23 and 12.0.1.0 to 12.0.9.0, as well as IBM Integration Bus for z/OS version 10.1 to 10.1.0.2.
What types of information might be exposed due to CVE-2024-22356?
CVE-2024-22356 may expose potentially sensitive information stored in log or trace files that can be accessed by privileged users.
Is there a patch available for CVE-2024-22356?
Yes, IBM has released several patches for each affected version to address the vulnerability identified by CVE-2024-22356.