5.1
CVE-2025-13491
- EPSS 0.01%
- Veröffentlicht 05.02.2026 14:16:03
- Zuletzt bearbeitet 15.04.2026 00:35:42
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM App Connect Enterprise Certified Container Information Disclosure
IBM App Connect Enterprise Certified Container CD: 11.2.0 through 11.6.0, 12.1.0 through 12.19.0 and 12.0 LTS: 12.0.0 through 12.0.19 could allow an attacker to access sensitive files or modify configurations due to an untrusted search path.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerIBM
≫
Produkt
App Connect Enterprise Certified Container
Default Statusunaffected
Version <=
11.6.0
Version
11.2.0
Status
affected
Version <=
12.19.0
Version
12.1.0
Status
affected
Version <=
12.0.19
Version
12.0.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.01% | 0.002 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@us.ibm.com | 5.1 | 2.5 | 2.5 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
CWE-426 Untrusted Search Path
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.