Skip to content
Threat Feed
high advisory

Multiple Vulnerabilities in IBM App Connect Enterprise

IBM App Connect Enterprise contains multiple vulnerabilities including CVE-2024-45063, CVE-2024-45064, and CVE-2024-45065, which may allow attackers to bypass security, conduct denial-of-service, or disclose sensitive information.

CVE search metadata

CVE search record: CVE-2024-45063. Severity: high. CVSS: 8.8. EPSS: 0.52%. KEV: no. Product: App Connect Enterprise. Brief: Multiple Vulnerabilities in IBM App Connect Enterprise. Brief link: https://feed.craftedsignal.io/briefs/2026-10-ibm-ace-vulnerabilities/

CVE search record: CVE-2024-45064. Severity: high. CVSS: 8.5. EPSS: 1.11%. KEV: no. Product: App Connect Enterprise. Brief: Multiple Vulnerabilities in IBM App Connect Enterprise. Brief link: https://feed.craftedsignal.io/briefs/2026-10-ibm-ace-vulnerabilities/

CVE search record: CVE-2024-45065. KEV: no. Product: App Connect Enterprise. Brief: Multiple Vulnerabilities in IBM App Connect Enterprise. Brief link: https://feed.craftedsignal.io/briefs/2026-10-ibm-ace-vulnerabilities/

IBM has disclosed multiple security vulnerabilities affecting IBM App Connect Enterprise. These vulnerabilities, identified as CVE-2024-45063, CVE-2024-45064, and CVE-2024-45065, present significant risks to organizational infrastructure. An unauthenticated remote attacker could leverage these flaws to bypass established security controls, execute a denial-of-service attack against the application, or perform unauthorized information disclosure. Given the critical role of App Connect Enterprise in integration and workflow automation, successful exploitation could compromise sensitive business data flows or lead to application downtime. Organizations currently running IBM App Connect Enterprise are advised to review the official IBM security bulletins to determine specific version vulnerability and apply the necessary patches provided by the vendor.

Impact

Successful exploitation of these vulnerabilities could lead to a complete denial of service for integration services, unauthorized exposure of internal configuration or application data, and the circumvention of security authentication measures. This poses a risk to organizations relying on IBM App Connect Enterprise for critical middleware operations, potentially affecting data integrity and service availability across the enterprise landscape.

Recommendation

  • Review current IBM App Connect Enterprise deployments against the list of affected versions provided by IBM in the official security bulletins for CVE-2024-45063, CVE-2024-45064, and CVE-2024-45065.
  • Apply available security updates or patches immediately as recommended by IBM to mitigate the risk of remote exploitation.
  • Monitor enterprise application logs for anomalous traffic patterns or unexpected service instability that could indicate exploitation attempts related to these CVEs.

Mitigations

Upgrade IBM App Connect Enterprise to the latest version as specified in IBM security advisories.

immediate IT Operations

CVE-2024-45063, CVE-2024-45064, CVE-2024-45065