Known vulnerabilities in IBM App Connect Enterprise - page 18

Software CPE: cpe:2.3:a:ibm_corporation:ibm_app_connect_enterprise:*:*:*:*:*:*:*:*
Total vulnerabilities: 361
Public exploits: 34
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM App Connect Enterprise IBM App Connect Enterprise is affected by 361 known vulnerabilities: 4 critical, 44 high, 229 medium, 84 low Critical High Medium Low

Vulnerabilities (361)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU65282 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-32215
CWE-444 Medium
No
No
- 13.07.2022 SB2022071338
SB2022071610
SB2022071611
and 54 more
#VU65278 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-32214
CWE-444 Medium
No
No
- 13.07.2022 SB2022071338
SB2022071610
SB2022071611
and 36 more
#VU64915 - Resource exhaustion
CVE-2022-44906
CWE-400 Medium
No
No
11.0.0.18, 12.0.4.0 05.07.2022 SB2022070501
#VU64696 - Improper input validation
CVE-2022-21803
CWE-20 Medium
No
No
11.0.0.18, 12.0.5.0 27.06.2022 SB2022062917
SB2022062928
SB2022062931
and 5 more
#VU64030 - Resource exhaustion
CVE-2021-44906
CWE-400 High
No
No
11.0.0.18, 12.0.4.0 07.06.2022 SB2022060836
SB2022062103
SB2022062203
and 52 more
#VU62768 - Uncontrolled Memory Allocation
CVE-2022-1473
CWE-789 Low
No
No
12.0.5.0 03.05.2022 SB2022050315
SB2022050436
SB2022050532
and 18 more
#VU62767 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2022-1434
CWE-300 Low
No
No
12.0.5.0 03.05.2022 SB2022050315
SB2022050436
SB2022050532
and 10 more
#VU62766 - Security Features
CVE-2022-1343
CWE-254 Medium
No
No
12.0.5.0 03.05.2022 SB2022050315
SB2022050436
SB2022050532
and 14 more
#VU62361 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-43138
CWE-94 Medium
No
No
11.0.0.18, 12.0.5.0 15.04.2022 SB2022041532
SB2022041533
SB2022062103
and 33 more
#VU61799 - Out-of-bounds write
CVE-2020-36518
CWE-787 Medium
No
No
11.0.0.18, 12.0.5.0 01.04.2022 SB2022040113
SB2022040114
SB2022040115
and 147 more
#VU61471 - Exposure of sensitive information to an unauthorized actor
CVE-2022-0235
CWE-200 Low
No
No
11.0.0.16 20.03.2022 SB2022032001
SB2022032002
SB2022032009
and 35 more
#VU61391 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2022-0778
CWE-835 Medium
Available
No
- 15.03.2022 SB2022031520
SB2022031522
SB2022031611
and 238 more
#VU60166 - Cryptographic Issues
CVE-2021-4160
CWE-310 Low
No
No
11.0.0.17, 12.0.4.0 28.01.2022 SB2022012811
SB2022031611
SB2022042517
and 29 more
#VU59548 - Improper Certificate Validation
CVE-2021-44531
CWE-295 Medium
No
No
11.0.0.16 12.01.2022 SB2022011216
SB2022032010
SB2022041522
and 35 more
#VU59098 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-44832
CWE-94 Medium
No
No
- 28.12.2021 SB2021122816
SB2021123002
SB2022010601
and 197 more
#VU58976 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-45046
CWE-94 High
Available
Exploited
- 15.12.2021 SB2021121504
SB2021121511
SB2021121512
and 178 more
#VU55560 - Use After Free
CVE-2021-22930
CWE-416 High
No
No
11.0.0.14, 12.0.2.0 03.08.2021 SB2021080320
SB2021080324
SB2021080325
and 35 more
#VU54625 - Incorrect Default Permissions
CVE-2021-22921
CWE-276 Low
No
No
11.0.0.14, 12.0.2.0 08.07.2021 SB2021100417
SB2022031104
SB2022060315
and 7 more
#VU54624 - Out-of-bounds read
CVE-2021-22918
CWE-125 Medium
No
No
11.0.0.14, 12.0.2.0 08.07.2021 SB2021070819
SB2021072009
SB2021081123
and 40 more
#VU27960 - Deserialization of Untrusted Data
CVE-2019-17571
CWE-502 High
No
No
- 18.05.2020 SB2019122027
SB2020051806
SB2020011497
and 28 more


Showing elements 341 - 360 out of 361