8.8
CVE-2025-36361
- EPSS 0.04%
- Veröffentlicht 24.10.2025 09:35:20
- Zuletzt bearbeitet 28.10.2025 14:27:33
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM App Connect Enterprise runtime is vulnerable to a lack of authorization on windows environments using IWA
IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user to perform unauthorized actions on customer defined resources due to missing authorization.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ App Connect Enterprise Version >= 12.0.1.0 <= 12.0.12.17
Ibm ≫ App Connect Enterprise Version >= 13.0.1.0 <= 13.0.4.2
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.114 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| psirt@us.ibm.com | 6.3 | 2.8 | 3.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.