CVE-2022-42439
06.02.2023, 21:15
IBM App Connect Enterprise 11.0.0.17 through 11.0.0.19 and 12.0.4.0 and 12.0.5.0 contains an unspecified vulnerability in the Discovery Connector nodes which may cause a 3rd party systems credentials to be exposed to a privileged attacker. IBM X-Force ID: 238211.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | app_connect_enterprise | 11.0.0.17 ≤ 𝑥 ≤ 11.0.0.19 |
ibm | app_connect_enterprise | 12.0.4.0 |
ibm | app_connect_enterprise | 12.0.5.0 |
ibm | app_connect_enterprise_certified_container | 4.1 |
ibm | app_connect_enterprise_certified_container | 4.2 |
ibm | app_connect_enterprise_certified_container | 5.0 |
ibm | app_connect_enterprise_certified_container | 5.1 |
ibm | app_connect_enterprise_certified_container | 5.2 |
ibm | app_connect_enterprise_certified_container | 6.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
- CWE-532 - Insertion of Sensitive Information into Log FileInformation written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.