CVE-2023-40682

Severity
4.4MEDIUM
EPSS
0.0%
top 95.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 13

Description

IBM App Connect Enterprise 12.0.1.0 through 12.0.8.0 contains an unspecified vulnerability that could allow a local privileged user to obtain sensitive information from API logs. IBM X-Force ID: 263833.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 0.8 | Impact: 3.6

Affected Packages2 packages

NVDibm/app_connect_enterprise12.0.1.012.0.9.0
CVEListV5ibm/app_connect_enterprise12.0.1.012.0.8.0

🔴Vulnerability Details

2
CVEList
IBM App Connect Enterprise information disclosure2023-10-13
GHSA
GHSA-4hqp-42w7-3hv5: IBM App Connect Enterprise 122023-10-13
CVE-2023-40682 (MEDIUM CVSS 4.4) | IBM App Connect Enterprise 12.0.1.0 | cvebase.io