First published: Wed May 22 2024(Updated: )
IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user information using an expired access token. IBM X-Force ID: 288176.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM App Connect | >=12.0.1.0<12.0.12.2 | |
IBM App Connect | <=12.0.1.0 - 12.0.12.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31895 is considered a medium severity vulnerability.
You can fix CVE-2024-31895 by applying the patches provided by IBM for App Connect Enterprise versions 12.0.1.0 to 12.0.12.1.
Authenticated users of IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.1 are affected by CVE-2024-31895.
CVE-2024-31895 could allow an authenticated user to obtain sensitive user information using an expired access token.
CVE-2024-31895 impacts IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.1.