Executive brief
IBM App Connect Enterprise, a platform used to integrate applications and data across different systems, is vulnerable to a security flaw that allows unauthorized access to files. A remote attacker could exploit this to read sensitive system files or application data without needing a password. This could lead to the exposure of confidential business information or credentials stored on the server.
Technical details
A path traversal vulnerability (CWE-22) exists in IBM App Connect Enterprise versions 12.0 and 13.0. The flaw allows a remote attacker to bypass directory restrictions and access files outside of the intended application scope by using specially crafted input. The attack vector is network-based and requires no authentication or user interaction. Successful exploitation results in the unauthorized disclosure of arbitrary files from the server's file system. IBM has released fix packs 13.0.8.0 and 12.0.12.28 to remediate this issue.
Affected products
- IBM App Connect Enterprise 13.0.1.0 - 13.0.7.2
- IBM App Connect Enterprise 12.0.1.0 - 12.0.12.27
Timeline
- 2026-07-29: patched: Modified date listed in advisory
- 2026-07-30: disclosed: Initial publication date