CVE-2026-16180

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 Toolkit could allow an authenticated user to cause a denial-of-service condition due to improper validation of XML entities.
References
Link Resource
https://www.ibm.com/support/pages/node/7286372 Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:app_connect_enterprise:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:app_connect_enterprise:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:integration_bus_for_z\/os:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-09-04 17:16

Updated : 2026-09-09 14:43


NVD link : CVE-2026-16180

Mitre link : CVE-2026-16180

CVE.ORG link : CVE-2026-16180


JSON object : View

Products Affected

ibm

  • app_connect_enterprise
  • integration_bus_for_z\/os
CWE
CWE-776

Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')