Multiple Vulnerabilities in IBM App Connect Enterprise
IBM App Connect Enterprise is affected by multiple vulnerabilities, including CVE-2024-45090 through CVE-2024-45094, which enable security bypass, denial-of-service, information disclosure, file manipulation, and cross-site scripting.
CVE search metadata
CVE search record: CVE-2024-45094. Severity: medium. CVSS: 5.5. EPSS: 0.21%. KEV: no. Product: App Connect Enterprise. Brief: Multiple Vulnerabilities in IBM App Connect Enterprise. Brief link: https://feed.craftedsignal.io/briefs/2026-09-ibm-app-connect-vulnerabilities/
CVE search record: CVE-2024-45091. Severity: medium. CVSS: 6.2. EPSS: 0.21%. KEV: no. Product: App Connect Enterprise. Brief: Multiple Vulnerabilities in IBM App Connect Enterprise. Brief link: https://feed.craftedsignal.io/briefs/2026-09-ibm-app-connect-vulnerabilities/
IBM has released a security advisory regarding multiple vulnerabilities affecting IBM App Connect Enterprise. The identified vulnerabilities, tracked as CVE-2024-45090, CVE-2024-45091, CVE-2024-45092, CVE-2024-45093, and CVE-2024-45094, allow unauthenticated or authenticated attackers to compromise the integrity and availability of the application.
These flaws permit a wide range of malicious activities, including the bypassing of existing security controls, triggering denial-of-service (DoS) conditions that disrupt service availability, unauthorized information disclosure of sensitive data, arbitrary file manipulation, and the execution of cross-site scripting (XSS) attacks. Defenders should prioritize auditing instances of IBM App Connect Enterprise for these specific CVEs and ensure that security patches are applied to mitigate the risk of unauthorized access or service disruption.
Immediate actions
Inventory all IBM App Connect Enterprise deployments.
Mitigations
Patch IBM App Connect Enterprise to the latest version as directed by the vendor.
CVE-2024-45090, CVE-2024-45091, CVE-2024-45092, CVE-2024-45093, CVE-2024-45094