CVE-2026-19649
- EPSS 0.12%
- Veröffentlicht 04.09.2026 15:18:16
- Zuletzt bearbeitet 09.09.2026 14:55:42
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of database credenti...
CVE-2026-78543
- EPSS 0.36%
- Veröffentlicht 04.09.2026 15:10:34
- Zuletzt bearbeitet 09.09.2026 14:50:54
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote attacker to cause a denial of service due to an infinite loop.
CVE-2026-81832
- EPSS 0.28%
- Veröffentlicht 04.09.2026 15:07:39
- Zuletzt bearbeitet 08.09.2026 21:59:22
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 SAP Adapter is vulnerable to an XML external entity (XXE) attack.
CVE-2026-12947
- EPSS 0.4%
- Veröffentlicht 30.07.2026 14:17:30
- Zuletzt bearbeitet 05.08.2026 14:50:01
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores potentially sensitive information in log files that could be read by a local user.
CVE-2026-15435
- EPSS 0.73%
- Veröffentlicht 30.07.2026 14:08:36
- Zuletzt bearbeitet 05.08.2026 14:32:18
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to...
CVE-2026-14522
- EPSS 1.02%
- Veröffentlicht 30.07.2026 14:06:56
- Zuletzt bearbeitet 05.08.2026 14:39:44
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due to improper neutralization of CRLF characters.
CVE-2026-14519
- EPSS 0.62%
- Veröffentlicht 30.07.2026 14:05:31
- Zuletzt bearbeitet 05.08.2026 14:41:35
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to read arbitrary files due to a path traversal vulnerability.
CVE-2026-3602
- EPSS 0.19%
- Veröffentlicht 30.06.2026 19:19:47
- Zuletzt bearbeitet 20.07.2026 15:16:37
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is vulnerable to SQL injection. A remote attacker could socially engineer a user into accidentally creati...
CVE-2026-5515
- EPSS 0.1%
- Veröffentlicht 27.05.2026 12:58:13
- Zuletzt bearbeitet 02.06.2026 17:16:37
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log files that could be read by a local user.
CVE-2025-36361
- EPSS 0.21%
- Veröffentlicht 24.10.2025 09:35:20
- Zuletzt bearbeitet 28.10.2025 14:27:33
IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user to perform unauthorized actions on customer defined resources due to missing authorization.