Executive brief
IBM App Connect Enterprise, a platform used to integrate various business applications and data, is vulnerable to a critical security flaw. An unauthenticated remote attacker can exploit this to write unauthorized files onto the server's file system. This could lead to a complete system takeover, data loss, or significant operational disruption.
Technical details
A path traversal vulnerability (CWE-22) exists in IBM App Connect Enterprise versions 12.0 and 13.0. The flaw is caused by improper validation of user-supplied input in URL requests. A remote, unauthenticated attacker can send a specially crafted URL containing 'dot dot' sequences (/../) to bypass directory restrictions. This allows the attacker to write arbitrary files to the underlying operating system, potentially leading to remote code execution. IBM has released fix packs 13.0.8.0 and 12.0.12.28 to address this issue.
Affected products
- IBM App Connect Enterprise 13.0.1.0 - 13.0.7.2, 12.0.1.0 - 12.0.12.27
Timeline
- 2026-07-30: disclosed: Initial publication of the security bulletin by IBM.
- 2026-07-30: patched: Fixes released in versions 13.0.8.0 and 12.0.12.28.