Junglewise Threat Intelligence

CVE-2026-3602: IBM App Connect Enterprise SQL injection in toolkit

CVE-2026-3602 · Severity: medium · CVSS 4.7 · Published 2026-06-30

Executive brief

IBM App Connect Enterprise and Integration Bus, which are used to connect different business applications and data, are affected by a security flaw. An attacker could use social engineering to trick a user into performing actions that result in the creation of unauthorized files on the system. This could potentially lead to data integrity issues or unauthorized system changes if a user is successfully deceived.

Technical details

IBM App Connect Enterprise and IBM Integration Bus for z/OS are vulnerable to SQL injection, specifically categorized as CWE-73 (External Control of File Name or Path). The vulnerability exists within the toolkit component. An attacker could exploit this by socially engineering a user into performing specific actions that trigger the injection, leading to the accidental creation of files that the user may not be aware of. The attack vector is local with high complexity, requiring user interaction. IBM has released patches via APAR PH71150 for versions 13.x, 12.x, and 10.1.x.

Affected products

  • IBM App Connect Enterprise 13.0.1.0 - 13.0.7.2, 12.0.1.0 - 12.0.12.26
  • IBM Integration Bus for z/OS 10.1.0.0 - 10.1.0.7

Timeline

  • 2026-06-29: advisory: Initial publication by IBM
  • 2026-06-30: disclosed: NVD publication date

References

Related threats