CVE-2024-22317

CWE-3073 documents3 sources
Severity
9.1CRITICAL
EPSS
0.1%
top 74.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 18

Description

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.24 and 12.0.1.0 through 12.0.11.0 could allow a remote attacker to obtain sensitive information or cause a denial of service due to improper restriction of excessive authentication attempts. IBM X-Force ID: 279143.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.2

Affected Packages2 packages

CVEListV5ibm/app_connect_enterprise11.0.0.111.0.0.24+1
NVDibm/app_connect_enterprise11.0.0.111.0.0.24+1

Patches

🔴Vulnerability Details

2
CVEList
IBM App Connect Enterprise denial of service2024-01-18
GHSA
GHSA-rcrf-j4mf-2fp6: IBM App Connect Enterprise 112024-01-18
CVE-2024-22317 (CRITICAL CVSS 9.1) | IBM App Connect Enterprise 11.0.0.1 | cvebase.io