CVE-2023-47722

Severity
5.5MEDIUM
EPSS
0.0%
top 94.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 9

Description

IBM API Connect V10.0.5.3 and V10.0.6.0 stores user credentials in browser cache which can be read by a local user. IBM X-Force ID: 271912.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.5 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/api_connectV10.0.5.3, V10.0.6.0
NVDibm/api_connect10.0.5.3, 10.0.6.0+1

🔴Vulnerability Details

2
GHSA
GHSA-hq7q-jpfq-95p9: IBM API Connect V102023-12-09
CVEList
IBM API Connect information disclosure2023-12-09
CVE-2023-47722 (MEDIUM CVSS 5.5) | IBM API Connect V10.0.5.3 and V10.0 | cvebase.io