IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.
Advisories

No advisories yet.

Fixes

Solution

IBM strongly recommends addressing the vulnerability now by upgrading. Product(s)Affected Version RangeRemediated VersionInstructions / DownloadIBM API Connect V10.0.810.0.8.0 – 10.0.8.5iFix  Instructions: https://www.ibm.com/support/pages/node/7255318   10.0.8.1: https://ibm.biz/BdbtC6   10.0.8.2-ifix1: https://ibm.biz/BdbtCN   10.0.8.2-ifix2: https://ibm.biz/BdbtC7   10.0.8.3: https://ibm.biz/BdbtCW   10.0.8.4: https://ibm.biz/BdbtQc   10.0.8.5: https://ibm.biz/BdbtQB   IBM API Connect V10.010.0.11iFix https://ibm.biz/BdbtCw


Workaround

Workarounds and Mitigations Customers unable to install the interim fix should disable self-service sign-up on their Developer Portal if enabled, which will help minimise their exposure to this vulnerability.

History

Fri, 26 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 26 Dec 2025 13:30:00 +0000

Type Values Removed Values Added
Description IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.
Title Authentication bypass in IBM API Connect
First Time appeared Ibm
Ibm api Connect
Weaknesses CWE-305
CPEs cpe:2.3:a:ibm:api_connect:10.0.11.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:api_connect:10.0.8.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:api_connect:10.0.8.5:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm api Connect
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-12-26T14:40:40.703Z

Reserved: 2025-12-02T18:13:58.988Z

Link: CVE-2025-13915

cve-icon Vulnrichment

Updated: 2025-12-26T14:40:37.578Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-26T14:15:58.193

Modified: 2025-12-29T15:57:37.560

Link: CVE-2025-13915

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses