Executive brief
IBM App Connect Enterprise and IBM Integration Bus for z/OS are integration middleware products that connect applications and services. An improper logging vulnerability allows local attackers to read database credentials stored in cleartext in log files, potentially enabling unauthorized database access and data theft. This affects versions 12.0.1.0 through 12.0.12.28, 13.0.1.0 through 13.0.8.1, and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7.
Technical details
The vulnerability is a CWE-532 (Insertion of Sensitive Information into Log File) issue where database credentials are logged in cleartext. The attack vector is local with no privilege requirements, allowing any user on the affected system to read the log files and extract credentials. This is a confidentiality-only impact vulnerability requiring only local file system access to the log directory. Patches are available: IBM App Connect Enterprise v13 requires Fix Pack 13.0.8.2 or later, v12 requires Fix Pack 12.0.12.29 or later, and IBM Integration Bus for z/OS 10.1.0.7 has an interim fix available via IBM Fix Central (APAR IT49773).
Affected products
- IBM App Connect Enterprise 12.0.1.0 through 12.0.12.28, 13.0.1.0 through 13.0.8.1
- IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7
Timeline
- 2026-09-04: disclosed