Executive brief
IBM App Connect Enterprise is a middleware platform used for integrating business applications and services. A local attacker with user-level access can execute arbitrary code on the system by injecting malicious OS commands, potentially compromising application integrity and accessing sensitive data.
Technical details
The vulnerability is an OS command injection flaw (CWE-78) caused by improper neutralization of special elements in OS commands. It requires local access and user interaction (non-privileged preconditions), allowing an attacker to execute arbitrary code with the privileges of the application process. The attack vector is local; network exploitation is not possible. IBM has released fixes in App Connect Enterprise 13.0.8.1 and 12.0.12.28 addressing the issue via APAR IT49855.
Affected products
- IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, 12.0.1.0 through 12.0.12.27
Timeline
- 2026-09-14: disclosed
- 2026-09-07: patched: Fix Pack 13.0.8.1 and 12.0.12.28