CVE Database
/

CVE-2024-22356

Back to search

CVE-2024-22356

Published: Mar 26, 2024

Modified: Aug 5, 2024

PUBLISHED

CVSS v3.1

4.9

MEDIUM

Description

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.23, 12.0.1.0 through 12.0.9.0 and IBM Integration Bus for z/OS 10.1 through 10.1.0.2store potentially sensitive information in log or trace files that could be read by a privileged user. IBM X-Force ID: 280893.

VendorProductVersions

IBM

App Connect Enterprise

affected
11.0.0.1 - <= 11.0.0.23
affected
12.0.1.0 - <= 12.0.9.0

IBM

Integration Bus

affected
10.1 - <= 10.1.0.2

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

High

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

None

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now