First published: Wed May 22 2024(Updated: )
IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive calendar information using an expired access token. IBM X-Force ID: 288174.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM App Connect | >=12.0.1.0<12.0.12.2 | |
IBM App Connect | <=12.0.1.0 - 12.0.12.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31893 is categorized as a medium severity vulnerability.
To fix CVE-2024-31893, you should upgrade IBM App Connect Enterprise to version 12.0.12.2 or later.
The impact of CVE-2024-31893 allows an authenticated user to access sensitive calendar information using an expired access token.
CVE-2024-31893 affects users of IBM App Connect Enterprise versions from 12.0.1.0 to 12.0.12.1.
No official workaround is provided for CVE-2024-31893; the recommended action is to apply the software patch.