Junglewise Threat Intelligence

CVE-2026-17442: IBM App Connect Enterprise cleartext credentials in trace logs

CVE-2026-17442 · Severity: medium · CVSS 5.1 · Published 2026-09-04

Executive brief

IBM App Connect Enterprise and IBM Integration Bus for z/OS are middleware platforms that route and transform business messages between applications. A vulnerability allows local attackers to recover database and integration credentials in plaintext from system trace logs, potentially enabling unauthorized access to backend systems and sensitive data theft.

Technical details

This is an information disclosure vulnerability stemming from improper logging of sensitive credentials (CWE-532). Credentials are written to trace logs in cleartext, which an attacker with local file system access can read. The vulnerability requires local access (not remote) and no authentication, but does require some ability to access log files. The attack achieves credential disclosure, which can lead to lateral movement and unauthorized database/system access. Fixes are available via APAR IT49773 as part of App Connect Enterprise v13.0.8.2, v12.0.12.29, and an interim fix for Integration Bus for z/OS 10.1.0.7.

Affected products

  • IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, 12.0.1.0 through 12.0.12.28
  • IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7

Timeline

  • 2026-09-04: disclosed
  • 2026-09-04: patched: APAR IT49773 released as part of v13.0.8.2, v12.0.12.29, and interim fix for z/OS 10.1.0.7

References

Related threats