Vulnerability Details CVE-2024-31894
IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user information using an expired access token. IBM X-Force ID: 288175.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 33.1%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2024-31894
-
cpe:2.3:a:ibm:app_connect_enterprise:12.0.1.0
-
cpe:2.3:a:ibm:app_connect_enterprise:12.0.10.0
-
cpe:2.3:a:ibm:app_connect_enterprise:12.0.11.0
-
cpe:2.3:a:ibm:app_connect_enterprise:12.0.11.1
-
cpe:2.3:a:ibm:app_connect_enterprise:12.0.11.2
-
cpe:2.3:a:ibm:app_connect_enterprise:12.0.11.3
-
cpe:2.3:a:ibm:app_connect_enterprise:12.0.12.0
-
cpe:2.3:a:ibm:app_connect_enterprise:12.0.12.1
-
cpe:2.3:a:ibm:app_connect_enterprise:12.0.2.0
-
cpe:2.3:a:ibm:app_connect_enterprise:12.0.3.0
-
cpe:2.3:a:ibm:app_connect_enterprise:12.0.4.0
-
cpe:2.3:a:ibm:app_connect_enterprise:12.0.5.0
-
cpe:2.3:a:ibm:app_connect_enterprise:12.0.6.0
-
cpe:2.3:a:ibm:app_connect_enterprise:12.0.7.0
-
cpe:2.3:a:ibm:app_connect_enterprise:12.0.8.0
-
cpe:2.3:a:ibm:app_connect_enterprise:12.0.9.0