First published: Wed May 22 2024(Updated: )
IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user information using an expired access token. IBM X-Force ID: 288175.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM App Connect Enterprise | <=12.0.1.0 - 12.0.12.1 | |
IBM App Connect Enterprise | >=12.0.1.0<12.0.12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31894 has a moderate severity rating as it allows authenticated users to access sensitive information with an expired access token.
CVE-2024-31894 affects users of IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.1.
To fix CVE-2024-31894, update to a version of IBM App Connect Enterprise that is 12.0.12.2 or later.
CVE-2024-31894 exploits access controls by allowing authenticated users to leverage expired tokens for information retrieval.
Using IBM App Connect Enterprise versions 12.0.1.0 to 12.0.12.1 poses a security risk until the vulnerability is patched.