Executive brief
IBM App Connect Enterprise, a platform used to integrate various business applications and data, is affected by a vulnerability where sensitive information is recorded in plain text within log files. This could allow an unauthorized person with access to the system's logs to view confidential data, potentially leading to further security breaches or data exposure. Organizations using Discovery Connector nodes are particularly at risk. IBM has released updates to address this issue and recommends upgrading to the latest fix packs.
Technical details
IBM App Connect Enterprise is vulnerable to sensitive information disclosure (CWE-532) within its Discovery Connector nodes. The application incorrectly records potentially sensitive data into log files, which may be accessible to local users or through log management interfaces. While the CVSS vector provided by the vendor indicates a network attack vector (AV:N), the description specifically highlights risks from local users reading log files. An attacker who gains access to these logs can extract confidential information, which could facilitate further attacks. The issue is resolved in IBM App Connect Enterprise versions 13.0.8.0 and 12.0.12.28.
Affected products
- IBM App Connect Enterprise 13.0.1.0 - 13.0.7.2
- IBM App Connect Enterprise 12.0.1.0 - 12.0.12.27
Timeline
- 2026-07-23: advisory: Initial publication by IBM
- 2026-07-30: disclosed: NVD publication date