IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive calendar information using an expired access token. IBM X-Force ID: 288174.
The product uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.
Name | Vendor | Start Version | End Version |
---|---|---|---|
App_connect_enterprise | Ibm | 12.0.1.0 (including) | 12.0.12.2 (excluding) |