Impact
IBM App Connect Enterprise is vulnerable to insecure deserialization, allowing a local attacker to execute arbitrary code on the host. The flaw is a classic unsafe deserialization issue, identified as CWE-502, which can lead to complete compromise of confidentiality, integrity, and availability within the victim system.
Affected Systems
Affected are IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.27 and 13..8.0 The recommended fix is the IT49855 APAR, available in Fix Pack 13.0.8.1 for the 13.x line and 12.0.12.28 for the 12.x line.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the vulnerability requires local access and no remote attack vector is described. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting currently limited known exploitation but the risk remains significant for systems with local user access.
OpenCVE Enrichment