Impact
This vulnerability is a path‑traversal flaw that allows a remote attacker to read files on the host filesystem. The flaw can be triggered by supplying specially crafted input to the application, resulting in a confidentiality breach if critical files are read. The weakness is identified as CWE‑22, indicating unsanitized path handling.
Affected Systems
IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.27 and 13.0.1.0 through 13.0.7.2 are affected. The issue is fixed in Fix Pack release 12.0.12.28 for the 12.x line and 13.0.8.0 for the 13.x line, which include the APAR IT49745.
Risk and Exploitability
The CVSS score of 7.5 denotes a high severity vulnerability. The EPSS score of < 1% indicates a very low but nonzero probability of exploitation, and the lack of a KEV listing suggests no confirmed public exploitation yet. Attackers could exploit the flaw from a remote position, most likely via HTTP endpoints exposed by the App Connect Enterprise instance. Inferred from the description, access to the application through a network interface would be required.
OpenCVE Enrichment