Skip to main content

Vendor/product archive

ibm / app_connect_enterprise CVEs

Beta · best-effort

17 CVEs tagged to ibm / app_connect_enterprise1 Critical, 0 High, 16 Medium, 0 Low, 0 Unrated.

CVE-2026-5515

Published May 27, 2026

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log files that could be read by a local user.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36361

Published Oct 24, 2025

IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user to perform unauthorized actions on customer defined resourc…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0799

Published Feb 6, 2025

IBM App Connect enterprise 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1 could allow an authenticated user to write to an arbitrary file on the system during bar confi…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-31895

Published May 22, 2024

IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user information using an expired access token. IBM X-Force ID: 28817…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31894

Published May 22, 2024

IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user information using an expired access token. IBM X-Force ID: 28817…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31904

Published May 22, 2024

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 integration nodes could allow an authenticated user to cause a denial of service due to an unc…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31893

Published May 22, 2024

IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive calendar information using an expired access token. IBM X-Force ID: 2…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28761

Published May 14, 2024

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which whe…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28760

Published May 14, 2024

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 dashboard is vulnerable to a denial of service due to improper restrictions of resource alloca…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22317

Published Jan 18, 2024

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.24 and 12.0.1.0 through 12.0.11.0 could allow a remote attacker to obtain sensitive information or cause a denial of service due…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-40682

Published Oct 13, 2023

IBM App Connect Enterprise 12.0.1.0 through 12.0.8.0 contains an unspecified vulnerability that could allow a local privileged user to obtain sensitive information from API logs.…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-17 of 17 CVEsPage 1 of 1