Impact
IBM App Connect Enterprise and IBM Integration Bus for z/OS Toolkit contain a flaw that permits an authenticated user to trigger a denial‑of‑service by sending XML documents that lack proper entity validation. The handling of XML entities can exhaust system resources or cause the application to hang, leading to an interruption of integration services.
Affected Systems
The vulnerability applies to IBM App Connect Enterprise versions 13.0.1.0 through 13.0.8.1 and 12.0.1.0 through 12.0.12.28, as well as to IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7. The intended fix is delivered in fix packs 13.0.8.2 (for 13.x) and 12.0.12.29 (for 12.x), and an interim fix is available for 10.1.0.7.
Risk and Exploitability
The CVSS score of 5.7 indicates moderate severity; the EPSS score is not available, so the likelihood of exploitation is uncertain, and the vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated to use the weakness, most likely through an existing account or a privileged user, and then craft malicious XML to trigger resource exhaustion or a hang. Successful exploitation would produce a denial of service at the node level, disrupting integration services for any users that depend on the affected component.
OpenCVE Enrichment