CRITICAL🇵🇱 Wersja polska

CVE-2024-22317

CVSS 9.1v3.1pub. 2024-01-18upd. 2024-11-21

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.24 and 12.0.1.0 through 12.0.11.0 could allow a remote attacker to obtain sensitive information or cause a denial of service due to improper restriction of excessive authentication attempts. IBM X-Force ID: 279143.

🤖 AI Analysis
How it works

The vulnerability mechanism (CWE-307) consists of a lack of proper limitation on excessive login attempts. An unauthenticated remote attacker can send an unlimited number of authentication requests to the vulnerable system, leading to resource exhaustion (DoS) or — through brute-force techniques — to disclosure of sensitive information. The absence of an account locking mechanism or request rate limiting enables the attack to be carried out without any privileges and without user interaction.

Impact

An attacker can cause service unavailability (DoS) or gain access to sensitive information processed by IBM App Connect Enterprise, compromising the integrity and confidentiality of organizational data.

Mitigation & patch

Apply patches available from the vendor in accordance with the references (https://www.ibm.com/support/pages/node/7108661). It is recommended to update to versions outside the vulnerable ranges indicated by IBM.

Who is affected

IBM App Connect Enterprise in versions 11.0.0.1 to 11.0.0.24 and 12.0.1.0 to 12.0.11.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
  • IBM App Connect Enterprise

    APP
    Ibm
    11.0.0.1 – 11.0.0.2412.0.1.0 – 12.0.11.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2026-15435CRITICAL9.8PL ✓same product

Path Traversal w IBM App Connect Enterprise umożliwiający zapis dowolnych plików

CVE-2026-12947HIGH7.5PL ✓same product

IBM App Connect Enterprise – ujawnienie wrażliwych danych w plikach logów

CVE-2026-14522HIGH8.8PL ✓same product

IBM App Connect Enterprise — command injection przez znaki CRLF

CVE-2026-14519HIGH7.5PL ✓same product

IBM App Connect Enterprise — path traversal umożliwia odczyt dowolnych plików

CVE-2026-3602MEDIUM4.7same product

IBM App Connect Enterprise w wersjach 13.0.1.0 do 13.0.7.2, 12.0.1.0 do 12.0.12.26 oraz IBM Integration Bus fo...