Executive brief
IBM App Connect Enterprise is a middleware platform used to connect and integrate business applications across enterprises. A local attacker can execute arbitrary code on systems running vulnerable versions by exploiting insecure deserialization of untrusted data. This allows an attacker to completely compromise the application server, potentially exposing sensitive business integration data and disrupting critical application connectivity.
Technical details
The vulnerability exists in IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.27 and 13.0.1.0 through 13.0.8.0 due to insecure deserialization of untrusted data (CWE-502). The vulnerability requires local access to the affected system and user interaction to exploit. An attacker with local access can craft malicious serialized objects that, when deserialized by the application, execute arbitrary code with the privileges of the App Connect Enterprise process. Patches are available in version 12.0.12.28 and 13.0.8.1 (via APAR IT49855).
Affected products
- IBM App Connect Enterprise 12.0.1.0 through 12.0.12.27, 13.0.1.0 through 13.0.8.0
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: Patch available in 12.0.12.28 and 13.0.8.1