Description
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to credentials being written to trace logs in cleartext.
Published: 2026-09-04
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises when IBM App Connect Enterprise and IBM Integration Bus for z/OS write authentication credentials to trace logs in cleartext. A local attacker gaining file‑system or application‑level access can read these logs to obtain usernames and passwords, which can then be leveraged for lateral movement or unauthorized system access. The weakness is a cleartext information disclosure that directly compromises credential confidentiality.

Affected Systems

Affected systems include IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.28 and 13.0.1.0 through 13.0.8.1, as well as IBM Integration Bus for z/OS versions 10.1.0.0 through 10.1.0.7. The APAR IT49773 and corresponding fix packs target all listed instances, providing a remediation path for these product lines.

Risk and Exploitability

The CVSS score is 5.1, reflecting a moderate severity that balances the local reach with significant data exposure risk. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the defect requires local execution, the attack surface is limited to privileged users or compromised accounts, but once exploited, the attacker can read credential information from logs. Prompt application of the supplied fix packs reduces the attack window and eliminates the cleartext credential leakage.

Generated by OpenCVE AI on September 4, 2026 at 18:27 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability/vulnerabilities now by applying the appropriate fix to IBM App Connect Enterprise and IBM Integration Bus for z/OS Affected Product(s)Version(s)APAR Remediation / Fixes IBM App Connect Enterprise13.0.1.0 - 13.0.8.1IT49773 The APAR (IT49773) is available from  IBM App Connect Enterprise v13- Fix Pack Release 13.0.8.2 https://www.ibm.com/support/pages/node/7285177 IBM App Connect Enterprise12.0.1.0 - 12.0.12.28IT49773 The APAR (IT49773) is available from  IBM App Connect Enterprise v12- Fix Pack Release 12.0.12.29 https://www.ibm.com/support/pages/node/7284253 IBM Integration Bus for z/OS10.1.0.0 - 10.1.0.7IT49773 Interim Fix for APAR (IT49773) is available to apply to 10.1.0.7 from IBM Fix Central https://www.ibm.com/support/fixcentral/swg/selectFixes


OpenCVE Recommended Actions

  • Apply the APAR (IT49773) fix pack for IBM App Connect Enterprise, upgrading to v13.0.8.2 or v12.0.12.29 as appropriate.
  • For IBM Integration Bus for z/OS, download and install the interim fix from IBM Fix Central to upgrade to or beyond 10.1.0.7.
  • Verify that trace logging configuration no longer records authentication credentials, and follow IBM’s guidance on secure logging practices.

Generated by OpenCVE AI on September 4, 2026 at 18:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to credentials being written to trace logs in cleartext.
Title IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
First Time appeared Ibm
Ibm app Connect Enterprise
Ibm integration Bus For Zos
Weaknesses CWE-532
CPEs cpe:2.3:a:ibm:app_connect_enterprise:12.0.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:app_connect_enterprise:12.0.12.28:*:*:*:*:*:*:*
cpe:2.3:a:ibm:app_connect_enterprise:13.0.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:app_connect_enterprise:13.0.8.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:integration_bus_for_zos:10.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:integration_bus_for_zos:10.1.0.7:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm app Connect Enterprise
Ibm integration Bus For Zos
References
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm App Connect Enterprise Integration Bus For Zos
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-04T16:36:02.961Z

Reserved: 2026-07-25T15:56:49.506Z

Link: CVE-2026-17442

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T17:16:54.020

Modified: 2026-09-04T17:16:54.020

Link: CVE-2026-17442

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T18:30:04Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File