IBM App Connect Enterprise 11.0.0.1 through 11.0.0.24 and 12.0.1.0 through 12.0.11.0 could allow a remote attacker to obtain sensitive information or cause a denial of service due to improper restriction of excessive authentication attempts. IBM X-Force ID: 279143.
The vulnerability mechanism (CWE-307) consists of a lack of proper limitation on excessive login attempts. An unauthenticated remote attacker can send an unlimited number of authentication requests to the vulnerable system, leading to resource exhaustion (DoS) or — through brute-force techniques — to disclosure of sensitive information. The absence of an account locking mechanism or request rate limiting enables the attack to be carried out without any privileges and without user interaction.
An attacker can cause service unavailability (DoS) or gain access to sensitive information processed by IBM App Connect Enterprise, compromising the integrity and confidentiality of organizational data.
Apply patches available from the vendor in accordance with the references (https://www.ibm.com/support/pages/node/7108661). It is recommended to update to versions outside the vulnerable ranges indicated by IBM.
IBM App Connect Enterprise in versions 11.0.0.1 to 11.0.0.24 and 12.0.1.0 to 12.0.11.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HIBM App Connect Enterprise
APPIbm11.0.0.1 – 11.0.0.2412.0.1.0 – 12.0.11.0
Related vulnerabilities
Path Traversal w IBM App Connect Enterprise umożliwiający zapis dowolnych plików
IBM App Connect Enterprise – ujawnienie wrażliwych danych w plikach logów
IBM App Connect Enterprise — command injection przez znaki CRLF
IBM App Connect Enterprise — path traversal umożliwia odczyt dowolnych plików
IBM App Connect Enterprise w wersjach 13.0.1.0 do 13.0.7.2, 12.0.1.0 do 12.0.12.26 oraz IBM Integration Bus fo...