CVE-2024-31895: IBM App Connect Enterprise

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user information using an expired access token. IBM X-Force ID: 288176.

Affected products

  • IBM App Connect Enterprise: from 12.0.1.0, before 12.0.12.2 (fixed in 12.0.12.2)

Published 2024-05-22. Last modified 2026-06-17.