CVE-2024-49338

CVSS 3.1 Score 4.4 of 10 (medium)

Details

Published Jan 18, 2025
CWE ID 1323

Summary

CVE-2024-49338 is a vulnerability affecting IBM App Connect Enterprise versions 12.0.1.0 through 12.0.7.0 and 13.0.1.0. Under specific configurations, this issue enables privileged users to gain JMS (Java Message Service) credentials, potentially leading to unauthorized access or data breaches. These credentials can be exploited to interact with IBM App Connect Enterprise messaging systems, compromising sensitive information or causing disruptions to services. It is essential for organizations using these affected versions to apply appropriate patches or updates as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • App Connect Enterprise

Affected Vendors

  • IBM Corporation