CVE-2024-49338: IBM App Connect Enterprise information disclosure
IBM App Connect Enterprise 12.0.1.0 through 12.0.7.0and 13.0.1.0 under certain configurations could allow a privileged user to obtain JMS credentials.
Other sources
IBM App Connect Enterprise under certain configurations could allow a privileged user to obtain JMS credentials.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49338?
CVE-2024-49338 is considered a high severity vulnerability due to the potential exposure of JMS credentials to a privileged user.
How do I fix CVE-2024-49338?
To fix CVE-2024-49338, ensure you apply the appropriate patches provided by IBM for App Connect Enterprise versions 12.0.7.0 and 13.0.1.0.
What are the affected versions in CVE-2024-49338?
CVE-2024-49338 affects IBM App Connect Enterprise versions 12.0.1.0 through 12.0.7.0 and version 13.0.1.0 under certain configurations.
What permissions are required to exploit CVE-2024-49338?
Exploitation of CVE-2024-49338 requires a user to have privileged access within the IBM App Connect Enterprise system.
Does CVE-2024-49338 impact all configurations of IBM App Connect Enterprise?
No, CVE-2024-49338 only affects IBM App Connect Enterprise under certain configurations that enable the exposure of JMS credentials.