Impact
The vulnerability is a local confidentiality disclosure: IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.27 and 13.0.1.0 through 13.0.7.2 incorrectly store sensitive data in log files that local users can read. This can allow a user with local system access to view information that was not intended for the general user base, potentially revealing credentials, configuration details, or other confidential data. The weakness is classified as CWE-532.
Affected Systems
IBM App Connect Enterprise customers running any version from 12.0.1.0 through 12.0.12.27 or from 13.0.1.0 through 13.0.7.2 are affected. The specific APAR IT49670 applies to all affected releases. Patching requires installing Fix Pack 12.0.12.28 for the 12.x line or Fix Pack 13.0.8.0 for the 13.x line.
Risk and Exploitability
With a CVSS base score of 7.5 the vulnerability poses a high confidentiality risk. Because it is exploitable only by a local user who can read files on the host, the risk is limited to environments where users have read permission to the log directory. The EPSS score is < 1%, indicating a low probability of exploitation. The issue is not listed in the CISA KEV catalog, indicating no known widespread exploitation at this time. Local attackers could still extract the logged data, so remediation is recommended.
OpenCVE Enrichment