Impact
A remote authenticated attacker can exploit an XML external entity injection flaw in IBM App Connect Enterprise and IBM Integration Bus for z/OS, allowing the attacker to read sensitive information. The vulnerability is identified as CWE‑611 and does not elevate privileges beyond the authenticated user’s level. The CVSS score of 5.3 indicates a moderate security impact.
Affected Systems
Affected products include IBM App Connect Enterprise 12.0.1.0 through 12.0.12.28 and 13.0.1.0 through 13.0.8.1, as well as IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7. The vulnerability is specifically tied to the APAR IT49773 fix package for the Enterprise versions and an interim fix for the z/OS 10.1.0.7 release.
Risk and Exploitability
The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no widespread exploitation evidence. The attack vector requires remote access and valid authentication, limiting the attack surface to users with legitimate credentials. Once authenticated, an attacker can supply malicious XML that triggers external entity resolution, exposing the underlying resources that the application can access.
OpenCVE Enrichment