5.9

CVE-2025-36133

IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 through 12.0.14stores potentially sensitive information in log files during installation that could be read by a local user on the container.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmApp Connect Enterprise Certified Containers Operands Version12.0.9.0 Updater2 SwEditioncontinuous_delivery
IbmApp Connect Enterprise Certified Containers Operands Version12.0.9.0 Updater3 SwEditioncontinuous_delivery
IbmApp Connect Enterprise Certified Containers Operands Version12.0.10.0 Updater1 SwEditioncontinuous_delivery
IbmApp Connect Enterprise Certified Containers Operands Version12.0.10.0 Updater2 SwEditioncontinuous_delivery
IbmApp Connect Enterprise Certified Containers Operands Version12.0.10.0 Updater3 SwEditioncontinuous_delivery
IbmApp Connect Enterprise Certified Containers Operands Version12.0.11.1 Updater1 SwEditioncontinuous_delivery
IbmApp Connect Enterprise Certified Containers Operands Version12.0.11.2 Updater1 SwEditioncontinuous_delivery
IbmApp Connect Enterprise Certified Containers Operands Version12.0.11.3 Updater1 SwEditioncontinuous_delivery
IbmApp Connect Enterprise Certified Containers Operands Version12.0.12 Updater1 SwEditionlts
IbmApp Connect Enterprise Certified Containers Operands Version12.0.12 Updater10 SwEditionlts
IbmApp Connect Enterprise Certified Containers Operands Version12.0.12 Updater11 SwEditionlts
IbmApp Connect Enterprise Certified Containers Operands Version12.0.12 Updater12 SwEditionlts
IbmApp Connect Enterprise Certified Containers Operands Version12.0.12 Updater13 SwEditionlts
IbmApp Connect Enterprise Certified Containers Operands Version12.0.12 Updater14 SwEditionlts
IbmApp Connect Enterprise Certified Containers Operands Version12.0.12 Updater2 SwEditionlts
IbmApp Connect Enterprise Certified Containers Operands Version12.0.12 Updater3 SwEditionlts
IbmApp Connect Enterprise Certified Containers Operands Version12.0.12 Updater4 SwEditionlts
IbmApp Connect Enterprise Certified Containers Operands Version12.0.12 Updater5 SwEditionlts
IbmApp Connect Enterprise Certified Containers Operands Version12.0.12 Updater6 SwEditionlts
IbmApp Connect Enterprise Certified Containers Operands Version12.0.12 Updater7 SwEditionlts
IbmApp Connect Enterprise Certified Containers Operands Version12.0.12 Updater8 SwEditionlts
IbmApp Connect Enterprise Certified Containers Operands Version12.0.12 Updater9 SwEditionlts
IbmApp Connect Enterprise Certified Containers Operands Version12.0.12.0 Updater1 SwEditioncontinuous_delivery
IbmApp Connect Enterprise Certified Containers Operands Version12.0.12.0 Updater2 SwEditioncontinuous_delivery
IbmApp Connect Enterprise Certified Containers Operands Version12.0.12.2 Updater1 SwEditioncontinuous_delivery
IbmApp Connect Enterprise Certified Containers Operands Version12.0.12.3 Updater1 SwEditioncontinuous_delivery
IbmApp Connect Enterprise Certified Containers Operands Version12.0.12.4 Updater1 SwEditioncontinuous_delivery
IbmApp Connect Enterprise Certified Containers Operands Version12.0.12.5 Updater1 SwEditioncontinuous_delivery
IbmApp Connect Enterprise Certified Containers Operands Version13.0.1.0 Updater1 SwEditioncontinuous_delivery
IbmApp Connect Enterprise Certified Containers Operands Version13.0.1.0 Updater2 SwEditioncontinuous_delivery
IbmApp Connect Enterprise Certified Containers Operands Version13.0.1.1 Updater1 SwEditioncontinuous_delivery
IbmApp Connect Enterprise Certified Containers Operands Version13.0.2.0 Updater1 SwEditioncontinuous_delivery
IbmApp Connect Enterprise Certified Containers Operands Version13.0.2.1 Updater1 SwEditioncontinuous_delivery
IbmApp Connect Enterprise Certified Containers Operands Version13.0.2.2 Updater1 SwEditioncontinuous_delivery
IbmApp Connect Enterprise Certified Containers Operands Version13.0.2.2 Updater2 SwEditioncontinuous_delivery
IbmApp Connect Enterprise Certified Containers Operands Version13.0.3.0 Updater1 SwEditioncontinuous_delivery
IbmApp Connect Enterprise Certified Containers Operands Version13.0.3.1 Updater1 SwEditioncontinuous_delivery
IbmApp Connect Enterprise Certified Containers Operands Version13.0.4.0 Updater1 SwEditioncontinuous_delivery
IbmApp Connect Enterprise Certified Containers Operands Version13.0.4.1 Updater1 SwEditioncontinuous_delivery
IbmApp Connect Operator SwEditioncontinuous_delivery Version >= 9.2.0 <= 11.6.0
IbmApp Connect Operator SwEditionlts Version >= 12.0.0 < 12.15.0
IbmApp Connect Operator SwEditioncontinuous_delivery Version >= 12.1.0 < 12.15.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.01% 0.006
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
psirt@us.ibm.com 5.9 1.4 4
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.