Servers with IBM App Connect Enterprise can crash after attack

IBM's integration software App Connect Enterprise is vulnerable to attack via a security gap. A security patch is available for download.

listen Print view

(Image: Artur Szczybylo/Shutterstock.com)

1 min. read

Because a component in IBM App Connect Enterprise is vulnerable, attackers can attack servers.

Videos by heise

IBM's integration software controls the flow of information between different applications. In a post, the developers explain that the vulnerability (CVE-2024-37890 "high") affects the Node.jsws module. At this point, sending a request with multiple HTTP headers can cause a server crash (DoS).

The developers state that the vulnerability has been closed in App Connect Enterprise c12- Fix Pack Release 12.0.12.4. The developers' article does not mention any current attacks. Nevertheless, admins should update the software to the latest version as soon as possible.

(des)

Don't miss any news – follow us on Facebook, LinkedIn or Mastodon.

This article was originally published in German. It was translated with technical assistance and editorially reviewed before publication.