Executive brief
IBM App Connect Enterprise and Integration Bus for z/OS are integration middleware platforms used to connect business applications and services. An authenticated attacker can exploit an XML external entity (XXE) injection flaw to read sensitive files and extract confidential data from affected systems. Organizations using these products should apply the available patches immediately.
Technical details
The vulnerability is an XML External Entity (XXE) injection flaw (CWE-611) in IBM App Connect Enterprise adapter nodes. It requires network access and authentication; an authenticated attacker with access to the integration platform can craft malicious XML input to retrieve sensitive information such as configuration files, credentials, or other data accessible to the application process. The vulnerability affects App Connect Enterprise versions 13.0.1.0 through 13.0.8.1 and 12.0.1.0 through 12.0.12.28, as well as IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7. Patches are available as fix packs (13.0.8.2 and 12.0.12.29 for ACE, and APAR IT49773 for IIB).
Affected products
- IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, 12.0.1.0 through 12.0.12.28
- IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7
Timeline
- 2026-09-04: disclosed: Security bulletin published
- 2026-09-04: patched: Fix packs available: App Connect Enterprise 13.0.8.2, 12.0.12.29; IIB z/OS APAR IT49773