CVE-2024-31895: IBM App Connect Enterprise information disclosure
IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user information using an expired access token. IBM X-Force ID: 288176.
Other sources
IBM App Connect Enterprise could allow an authenticated user to obtain sensitive user information using an expired access token.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31895?
CVE-2024-31895 is considered a medium severity vulnerability.
How do I fix CVE-2024-31895?
You can fix CVE-2024-31895 by applying the patches provided by IBM for App Connect Enterprise versions 12.0.1.0 to 12.0.12.1.
Who is affected by CVE-2024-31895?
Authenticated users of IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.1 are affected by CVE-2024-31895.
What type of information can be exposed due to CVE-2024-31895?
CVE-2024-31895 could allow an authenticated user to obtain sensitive user information using an expired access token.
What versions of IBM App Connect Enterprise are impacted by CVE-2024-31895?
CVE-2024-31895 impacts IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.1.