First published: Mon Nov 11 2024(Updated: )
IBM App Connect Enterprise 12.0.1.0 through 12.0.7.0and 13.0.1.0 under certain configurations could allow a privileged user to obtain JMS credentials.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM App Connect | <=12.0.1.0 - 12.0.7.0 | |
IBM App Connect | <=13.0.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49338 is considered a high severity vulnerability due to the potential exposure of JMS credentials to a privileged user.
To fix CVE-2024-49338, ensure you apply the appropriate patches provided by IBM for App Connect Enterprise versions 12.0.7.0 and 13.0.1.0.
CVE-2024-49338 affects IBM App Connect Enterprise versions 12.0.1.0 through 12.0.7.0 and version 13.0.1.0 under certain configurations.
Exploitation of CVE-2024-49338 requires a user to have privileged access within the IBM App Connect Enterprise system.
No, CVE-2024-49338 only affects IBM App Connect Enterprise under certain configurations that enable the exposure of JMS credentials.