Impact
IBM App Connect Enterprise is vulnerable to insecure deserialization, allowing a local attacker to execute arbitrary code on the host. The flaw is identified as CWE-502, a classic unsafe deserialization issue that can lead to complete compromise of confidentiality, integrity, and availability within the victim system.
Affected Systems
Affected are IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.27 and 13.0.1.0 through 13.0.8.0. The recommended fix is the IT49855 APAR, available in Fix Pack 13.0.8.1 for the 13.x line and 12.0.12.28 for the 12.x line.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, yet the vulnerability requires local access. The EPSS score of 0.141% (reported as 0.00141) shows a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, indicating no known publicly documented exploitation but still a significant risk for systems with local user privileges.
OpenCVE Enrichment