Impact
The vulnerability in IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.27 and 13.0.1.0 through 13.0.8.0 allows a local attacker to execute arbitrary code by exploiting improper neutralization of special elements used in an OS command. This results in unrestricted command execution within the application’s runtime environment.
Affected Systems
This issue affects IBM App Connect Enterprise releases 12.0.1.0–12.0.12.27 and 13.0.1.0–13.0.8.0. The remediation is provided through APAR IT49855, which is available in IBM App Connect Enterprise v12‑Fix Pack 12.0.12.28 and v13‑Fix Pack 13.0.8.1.
Risk and Exploitability
The CVSS score of 7.8 marks this as high severity, although the EPSS score is not provided and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access, typically through an account that can run the application; a successful local attacker could compromise system integrity and, if higher privileges exist, achieve full system takeover.
OpenCVE Enrichment