Project Subscriptions
No advisories yet.
Solution
IBM strongly suggests the following: App Connect Enterprise Certified Container up to 12.19.0 (Continuous Delivery) Upgrade to App Connect Enterprise Certified Container Operator version 12.20.0 or higher, and ensure that all DesignerAuthoring components are at 13.0.6.1-r1 or higher. Documentation on the upgrade process is available at https://www.ibm.com/docs/en/app-connect/13.0?topic=releases-upgrading-operator App Connect Enterprise Certified Container 12.0 LTS (Long Term Support) Upgrade to App Connect Enterprise Certified Container Operator version 12.0.20 or higher, and ensure that all DesignerAuthoring components are at 12.0.12-r20 or higher. Documentation on the upgrade process is available at https://www.ibm.com/docs/en/app-connect/12.0?topic=umfpr-upgrading-operator-releases
Workaround
Disable mapping assistance in the DesignerAuthoring component
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7259746 |
|
Thu, 05 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 05 Feb 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM App Connect Enterprise Certified Container up to 12.19.0 (Continuous Delivery) and 12.0 LTS (Long Term Support) could allow an attacker to access sensitive files or modify configurations due to an untrusted search path. | |
| Title | IBM App Connect Enterprise Certified Container DesignerAuthoring operands that use mapping assistance are vulnerable to loss of confidentiality [] | |
| First Time appeared |
Ibm
Ibm app Connect Enterprisecertified Containers Operands Ibm app Connect Operator |
|
| Weaknesses | CWE-426 | |
| CPEs | cpe:2.3:a:ibm:app_connect_enterprisecertified_containers_operands:cd:12.0.11.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:app_connect_enterprisecertified_containers_operands:r1:*:*:*:*:*:*:* cpe:2.3:a:ibm:app_connect_operator:11.6.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:app_connect_operator:cd:11.2.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm app Connect Enterprisecertified Containers Operands Ibm app Connect Operator |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-02-05T14:46:23.152Z
Reserved: 2025-11-20T21:11:07.402Z
Link: CVE-2025-13491
Updated: 2026-02-05T14:46:15.328Z
Status : Awaiting Analysis
Published: 2026-02-05T14:16:03.940
Modified: 2026-02-05T14:57:20.563
Link: CVE-2025-13491
No data.
OpenCVE Enrichment
No data.