PT-2024-5326 · Ibm · Ibm App Connect Enterprise
Published
2024-05-21
·
Updated
2025-01-07
·
CVE-2024-31904
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
IBM App Connect Enterprise versions 11.0.0.1 through 11.0.0.25
IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.0
Description
The issue is related to an error in exception handling in the AdminAPI component of IBM App Connect Enterprise, which could allow an authenticated user to cause a denial of service due to an uncaught exception. This could be exploited by a remote attacker.
Recommendations
For IBM App Connect Enterprise versions 11.0.0.1 through 11.0.0.25, update to a version that includes the fix for this issue.
For IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.0, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the integration nodes to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm App Connect Enterprise