CVE-2024-31895
22.05.2024, 20:15
IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user information using an expired access token. IBM X-Force ID: 288176.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | app_connect_enterprise | 12.0.1.0 ≤ 𝑥 < 12.0.12.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-324 - Use of a Key Past its Expiration DateThe product uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.
- CWE-672 - Operation on a Resource after Expiration or ReleaseThe software uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.