CVE-2024-31893: IBM App Connect Enterprise information disclosure
IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive calendar information using an expired access token. IBM X-Force ID: 288174.
Other sources
IBM App Connect Enterprise could allow an authenticated user to obtain sensitive calendar information using an expired access token.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31893?
CVE-2024-31893 is categorized as a medium severity vulnerability.
How do I fix CVE-2024-31893?
To fix CVE-2024-31893, you should upgrade IBM App Connect Enterprise to version 12.0.12.2 or later.
What is the impact of CVE-2024-31893?
The impact of CVE-2024-31893 allows an authenticated user to access sensitive calendar information using an expired access token.
Who is affected by CVE-2024-31893?
CVE-2024-31893 affects users of IBM App Connect Enterprise versions from 12.0.1.0 to 12.0.12.1.
Is there a workaround for CVE-2024-31893?
No official workaround is provided for CVE-2024-31893; the recommended action is to apply the software patch.