Impact
The vulnerability arises from uncontrolled recursion that can be triggered by a local attacker, causing an application process to consume excessive stack space and crash. The impact is a disruption of service availability, allowing the attacker to deny legitimate users access to IBM App Connect Enterprise or IBM Integration Bus for z/OS. This weakness is classified as CWE‑674, a failure to limit recursion depth.
Affected Systems
IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.28 and 13.0.1.0 through 13.0.8.1 are affected, as well as IBM Integration Bus for z/OS version 10.1.0.0 through 10.1.0.7. All installations within these version ranges must be examined and patched accordingly.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score is not available, so exploit probability cannot be quantified, but the lack of KEV listing suggests no widely known exploits yet. The user is inferred to need local or privileged access to trigger exploitation; the attack vector is therefore local. Given the moderate score and absence of known public exploits, the risk is moderate pending patch deployment.
OpenCVE Enrichment