Impact
The vulnerability arises from improper logging of database credentials in IBM App Connect Enterprise versions 13.0.1.0 through 13.0.8.1 and 12.0.1.0 through 12.0.12.28, as well as in IBM Integration Bus for z/OS versions 10.1.0.0 through 10.1.0.7. A local attacker who can access the system can read the log files and obtain database usernames and passwords, exposing confidential data. The weakness is an instance of CWE-532: Log File Contains Sensitive Information.
Affected Systems
Affected products are IBM App Connect Enterprise (v13.x 13.0.1.0‑13.0.8.1 and v12.x 12.0.1.0‑12.0.12.28) and IBM Integration Bus for z/OS (v10.1.0.0‑10.1.0.7).
Risk and Exploitability
The CVSS score of 6.2 indicates a moderate severity, and the vulnerability is not listed in the CISA KEV catalog, with EPSS data not available. Because the vulnerability requires local system access, it is not exploitable remotely; however, a local attacker could leverage existing privileges to read log files, potentially compromising database credentials. The remediation is defined by the vendor and involves applying specific fix packs or an interim fix for the affected versions.
OpenCVE Enrichment