Description
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to read arbitrary files due to a path traversal vulnerability.
Published: 2026-07-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a path‑traversal flaw that allows a remote attacker to read files on the host filesystem. The flaw can be triggered by supplying specially crafted input to the application, resulting in a confidentiality breach if critical files are read. The weakness is identified as CWE‑22, indicating unsanitized path handling.

Affected Systems

IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.27 and 13.0.1.0 through 13.0.7.2 are affected. The issue is fixed in Fix Pack release 12.0.12.28 for the 12.x line and 13.0.8.0 for the 13.x line, which include the APAR IT49745.

Risk and Exploitability

The CVSS score of 7.5 denotes a high severity vulnerability. The EPSS score of < 1% indicates a very low but nonzero probability of exploitation, and the lack of a KEV listing suggests no confirmed public exploitation yet. Attackers could exploit the flaw from a remote position, most likely via HTTP endpoints exposed by the App Connect Enterprise instance. Inferred from the description, access to the application through a network interface would be required.

Generated by OpenCVE AI on August 2, 2026 at 05:21 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability/vulnerabilities now by applying the appropriate fix to IBM App Connect Enterprise Affected Product(s)Version(s)APARRemediation / FixesIBM App Connect Enterprise13.0.1.0 - 13.0.7.2IT49745 The APAR (IT49745) is available from IBM App Connect Enterprise v13- Fix Pack Release 13.0.8.0 https://www.ibm.com/support/pages/download-ibm-app-connect-enterprise-13080 IBM App Connect Enterprise12.0.1.0 - 12.0.12.27IT49745 The APAR (IT49745) is available from IBM App Connect Enterprise v12- Fix Pack Release 12.0.12.28 https://www.ibm.com/support/pages/download-ibm-app-connect-enterprise-1201228-fix-pack


OpenCVE Recommended Actions

  • Apply the IBM fix pack 12.0.12.28 for the 12.x series or 13.0.8.0 for the 13.x series, which resolves the path‑traversal issue.
  • If the patch cannot be applied immediately, tightly restrict network access to the App Connect Enterprise nodes and enforce authentication on all management interfaces to prevent unauthorized input.
  • Configure the application to validate file paths and ensure that only authorized resources can be accessed, mitigating the risk of unintended reads.

Generated by OpenCVE AI on August 2, 2026 at 05:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to read arbitrary files due to a path traversal vulnerability.
Title IBM App Connect Enterprise is vulnerable to an arbitrary file read and arbitrary changes to configuration settings
First Time appeared Ibm
Ibm app Connect Enterprise
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:app_connect_enterprise:12.0.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:app_connect_enterprise:12.0.12.27:*:*:*:*:*:*:*
cpe:2.3:a:ibm:app_connect_enterprise:13.0.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:app_connect_enterprise:13.0.7.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm app Connect Enterprise
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm App Connect Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-30T17:26:57.088Z

Reserved: 2026-07-02T19:36:02.265Z

Link: CVE-2026-14519

cve-icon Vulnrichment

Updated: 2026-07-30T17:26:51.914Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T15:16:25.547

Modified: 2026-08-05T14:41:35.393

Link: CVE-2026-14519

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T05:30:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')