Impact
The vulnerability arises when IBM App Connect Enterprise and IBM Integration Bus for z/OS write authentication credentials to trace logs in cleartext. A local attacker gaining file‑system or application‑level access can read these logs to obtain usernames and passwords, which can then be leveraged for lateral movement or unauthorized system access. The weakness is a cleartext information disclosure that directly compromises credential confidentiality.
Affected Systems
Affected systems include IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.28 and 13.0.1.0 through 13.0.8.1, as well as IBM Integration Bus for z/OS versions 10.1.0.0 through 10.1.0.7. The APAR IT49773 and corresponding fix packs target all listed instances, providing a remediation path for these product lines.
Risk and Exploitability
The CVSS score is 5.1, reflecting a moderate severity that balances the local reach with significant data exposure risk. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the defect requires local execution, the attack surface is limited to privileged users or compromised accounts, but once exploited, the attacker can read credential information from logs. Prompt application of the supplied fix packs reduces the attack window and eliminates the cleartext credential leakage.
OpenCVE Enrichment