Total
30 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-17444 | 1 Ibm | 2 App Connect Enterprise, Integration Bus For Z\/os | 2026-09-10 | N/A | 5.3 MEDIUM |
| IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection. | |||||
| CVE-2026-17442 | 1 Ibm | 2 App Connect Enterprise, Integration Bus For Z\/os | 2026-09-10 | N/A | 5.1 MEDIUM |
| IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to credentials being written to trace logs in cleartext. | |||||
| CVE-2026-17443 | 1 Ibm | 2 App Connect Enterprise, Integration Bus For Z\/os | 2026-09-09 | N/A | 5.3 MEDIUM |
| IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw. | |||||
| CVE-2026-19649 | 1 Ibm | 2 App Connect Enterprise, Integration Bus For Z\/os | 2026-09-09 | N/A | 6.2 MEDIUM |
| IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of database credentials. | |||||
| CVE-2026-78543 | 1 Ibm | 2 App Connect Enterprise, Integration Bus For Z\/os | 2026-09-09 | N/A | 5.3 MEDIUM |
| IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote attacker to cause a denial of service due to an infinite loop. | |||||
| CVE-2026-16180 | 1 Ibm | 2 App Connect Enterprise, Integration Bus For Z\/os | 2026-09-09 | N/A | 5.7 MEDIUM |
| IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 Toolkit could allow an authenticated user to cause a denial-of-service condition due to improper validation of XML entities. | |||||
| CVE-2026-17440 | 1 Ibm | 2 App Connect Enterprise, Integration Bus For Z\/os | 2026-09-09 | N/A | 5.5 MEDIUM |
| IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to cause a denial of service due to uncontrolled recursion. | |||||
| CVE-2026-81832 | 1 Ibm | 2 App Connect Enterprise, Integration Bus For Z\/os | 2026-09-08 | N/A | 7.7 HIGH |
| IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 SAP Adapter is vulnerable to an XML external entity (XXE) attack. | |||||
| CVE-2026-16689 | 1 Ibm | 2 App Connect Enterprise, Integration Bus For Z\/os | 2026-09-08 | N/A | 6.2 MEDIUM |
| IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of credentials. | |||||
| CVE-2026-12947 | 1 Ibm | 1 App Connect Enterprise | 2026-08-05 | N/A | 7.5 HIGH |
| IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores potentially sensitive information in log files that could be read by a local user. | |||||
| CVE-2026-14519 | 1 Ibm | 1 App Connect Enterprise | 2026-08-05 | N/A | 7.5 HIGH |
| IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to read arbitrary files due to a path traversal vulnerability. | |||||
| CVE-2026-14522 | 1 Ibm | 1 App Connect Enterprise | 2026-08-05 | N/A | 8.8 HIGH |
| IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due to improper neutralization of CRLF characters. | |||||
| CVE-2026-15435 | 1 Ibm | 1 App Connect Enterprise | 2026-08-05 | N/A | 9.8 CRITICAL |
| IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system. | |||||
| CVE-2026-3602 | 1 Ibm | 3 App Connect Enterprise, Integration Bus, Z\/os | 2026-07-20 | N/A | 4.7 MEDIUM |
| IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is vulnerable to SQL injection. A remote attacker could socially engineer a user into accidentally creating files they may not be aware of. | |||||
| CVE-2026-5515 | 1 Ibm | 1 App Connect Enterprise | 2026-06-17 | N/A | 5.5 MEDIUM |
| IBM App Connect Enterprise 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log files that could be read by a local user. | |||||
| CVE-2025-36361 | 1 Ibm | 1 App Connect Enterprise | 2026-06-17 | N/A | 6.3 MEDIUM |
| IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user to perform unauthorized actions on customer defined resources due to missing authorization. | |||||
| CVE-2025-0799 | 1 Ibm | 1 App Connect Enterprise | 2026-06-17 | N/A | 6.5 MEDIUM |
| IBM App Connect enterprise 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1 could allow an authenticated user to write to an arbitrary file on the system during bar configuration deployment due to improper pathname limitations on restricted directories. | |||||
| CVE-2024-49338 | 3 Ibm, Linux, Microsoft | 4 Aix, App Connect Enterprise, Linux Kernel and 1 more | 2026-06-17 | N/A | 4.4 MEDIUM |
| IBM App Connect Enterprise 12.0.1.0 through 12.0.7.0and 13.0.1.0 under certain configurations could allow a privileged user to obtain JMS credentials. | |||||
| CVE-2024-31904 | 1 Ibm | 1 App Connect Enterprise | 2026-06-17 | N/A | 6.5 MEDIUM |
| IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 integration nodes could allow an authenticated user to cause a denial of service due to an uncaught exception. IBM X-Force ID: 289647. | |||||
| CVE-2024-31895 | 1 Ibm | 1 App Connect Enterprise | 2026-06-17 | N/A | 4.3 MEDIUM |
| IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user information using an expired access token. IBM X-Force ID: 288176. | |||||
