Description
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores potentially sensitive information in log files that could be read by a local user.
Published: 2026-07-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a local confidentiality disclosure: IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.27 and 13.0.1.0 through 13.0.7.2 incorrectly store sensitive data in log files that local users can read. This can allow a user with local system access to view information that was not intended for the general user base, potentially revealing credentials, configuration details, or other confidential data. The weakness is classified as CWE-532.

Affected Systems

IBM App Connect Enterprise customers running any version from 12.0.1.0 through 12.0.12.27 or from 13.0.1.0 through 13.0.7.2 are affected. The specific APAR IT49670 applies to all affected releases. Patching requires installing Fix Pack 12.0.12.28 for the 12.x line or Fix Pack 13.0.8.0 for the 13.x line.

Risk and Exploitability

With a CVSS base score of 7.5 the vulnerability poses a high confidentiality risk. Because it is exploitable only by a local user who can read files on the host, the risk is limited to environments where users have read permission to the log directory. The EPSS score is < 1%, indicating a low probability of exploitation. The issue is not listed in the CISA KEV catalog, indicating no known widespread exploitation at this time. Local attackers could still extract the logged data, so remediation is recommended.

Generated by OpenCVE AI on August 2, 2026 at 05:18 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability/vulnerabilities now by applying the appropriate fix to IBM App Connect Enterprise Affected Product(s) Version(s) APAR Remediation / Fixes IBM App Connect Enterprise 13.0.1.0 - 13.0.7.2 IT49670 The APAR (IT49670) is available from IBM App Connect Enterprise v13- Fix Pack Release 13.0.8.0 https://www.ibm.com/support/pages/download-ibm-app-connect-enterprise-13080 IBM App Connect Enterprise 12.0.1.0 - 12.0.12.27 IT49670 The APAR (IT49670) is available from IBM App Connect Enterprise v12- Fix Pack Release 12.0.12.28 https://www.ibm.com/support/pages/download-ibm-app-connect-enterprise-1201228-fix-pack


OpenCVE Recommended Actions

  • Apply the IBM App Connect Enterprise Fix Pack 12.0.12.28 for the 12.x series or Fix Pack 13.0.8.0 for the 13.x series, which resolves the log data leakage (APAR IT49670).
  • If a patch cannot be applied immediately, restrict file system permissions on the log directories so that only privileged accounts can read sensitive logs (e.g., change ownership or set restrictive ACLs).
  • Disable or reconfigure Discovery Connector nodes to eliminate the logging of sensitive information, or replace the log handler with a secure variant that masks or omits such data.

Generated by OpenCVE AI on August 2, 2026 at 05:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores potentially sensitive information in log files that could be read by a local user.
Title IBM App Connect Enterprise is vulnerable to Confidentiality disclosure on Discovery Connector nodes
First Time appeared Ibm
Ibm app Connect Enterprise
Weaknesses CWE-532
CPEs cpe:2.3:a:ibm:app_connect_enterprise:12.0.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:app_connect_enterprise:12.0.12.27:*:*:*:*:*:*:*
cpe:2.3:a:ibm:app_connect_enterprise:13.0.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:app_connect_enterprise:13.0.7.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm app Connect Enterprise
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm App Connect Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-30T16:18:40.220Z

Reserved: 2026-06-22T20:31:54.377Z

Link: CVE-2026-12947

cve-icon Vulnrichment

Updated: 2026-07-30T16:18:37.433Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T15:16:24.427

Modified: 2026-08-05T14:50:01.547

Link: CVE-2026-12947

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T05:30:06Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File