Impact
The vulnerability is an insecure deserialization flaw (CWE-502) in IBM App Connect Enterprise that allows a local attacker to supply crafted data to the deserialization process, bypassing input validation and enabling execution of arbitrary code on the host. The flaw can lead to full compromise of confidentiality, integrity, and availability of the affected system.
Affected Systems
IBM App Connect Enterprise is affected in all releases from 12.0.1.0 through 12.0.12.27 and from 13.0.1.0 through 13.0.8.0. The APAR IT49855 fix is available in fix pack releases 12.0.12.28 and 13.0.8.1 and should be applied to eliminate the flaw.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Only a local attacker with the ability to influence data sent to the deserialization routine can exploit it; remote exploitation is not described. Once the flaw is triggered, the attacker gains full control over the App Connect Enterprise process.
OpenCVE Enrichment