Executive brief
IBM App Connect Enterprise, a platform used to integrate applications and data across different systems, is vulnerable to an information disclosure issue. The software incorrectly records sensitive data into log files that are accessible to users with local access to the system. This could allow an unauthorized person with basic system access to view confidential information, potentially leading to further security compromises.
Technical details
IBM App Connect Enterprise is vulnerable to an information disclosure vulnerability when using WS-Security with Java 17. The root cause is the improper storage of sensitive information within application log files. A local attacker with low privileges can read these logs to extract confidential data. The vulnerability affects versions 13.0.1.0 through 13.0.7.0 on AIX, Linux, and Windows platforms. Users should update to Fix Pack 13.0.7.1 (APAR IT49227) to remediate the issue.
Affected products
- IBM App Connect Enterprise 13.0.1.0 - 13.0.7.0
Timeline
- 2026-05-07: advisory: Initial publication by IBM
- 2026-05-27: disclosed: NVD publication date