Description
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is vulnerable to SQL injection. A remote attacker could socially engineer a user into accidentally creating files they may not be aware of.
Published: 2026-06-30
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a remote attacker to inject arbitrary SQL statements into the toolkit’s database queries through its interface, enabling reading, modification, or deletion of data in the connected databases. The engineering attack could also cause a user to unknowingly create potentially malicious files, indicating that the injection may be triggered through user interactions.

Affected Systems

IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.26 and 13.0.1.0 through 13.0.7.2, and IBM Integration Bus for z/OS versions 10.1.0.0 through 10.1.0.7.

Risk and Exploitability

The CVSS score of 4.7 places this issue in the Moderate severity range. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. A remote attacker can exploit the flaw by sending crafted input to the toolkit’s interface; socially engineered users may also be prompted to create files that exploit the injection.

Generated by OpenCVE AI on June 30, 2026 at 21:26 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability/vulnerabilities now by applying the appropriate fix to IBM App Connect Enterprise and IBM Integration Bus for z/OS Affected Product(s)Version(s)APARRemediation / FixesIBM App Connect Enterprise13.0.1.0 - 13.0.7.2PH71150The APAR (PH71150) is available fromIBM App Connect Enterprise v13- Fix Pack Release 13.0.8.0IBM App Connect Enterprise12.0.1.0 - 12.0.12.26 PH71150The APAR (PH71150) is available fromIBM App Connect Enterprise v12- Fix Pack Release 12.0.12.27IBM Integration Bus for z/OS10.1.0.0 - 10.1.0.7PH71150Interim Fix for APAR (PH71150) is available to apply to 10.1.0.7 from IBM Fix Central


OpenCVE Recommended Actions

  • Apply APAR PH71150 from IBM Fix Central for the specific product and version you are using.
  • Ensure that all users are operating the latest patched version of IBM App Connect Enterprise or IBM Integration Bus for z/OS.
  • Restrict or secure the network access to the toolkit’s database connections until the patch is applied.

Generated by OpenCVE AI on June 30, 2026 at 21:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 30 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 19:30:00 +0000

Type Values Removed Values Added
Description IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is vulnerable to SQL injection. A remote attacker could socially engineer a user into accidentally creating files they may not be aware of.
Title IBM App Connect Enterprise and IBM Integration Bus for z/OS toolkit is vulnerable to an sql injection
First Time appeared Ibm
Ibm app Connect Enterprise
Ibm integration Bus For Zos
Weaknesses CWE-73
CPEs cpe:2.3:a:ibm:app_connect_enterprise:12.0.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:app_connect_enterprise:12.0.12.26:*:*:*:*:*:*:*
cpe:2.3:a:ibm:app_connect_enterprise:13.0.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:app_connect_enterprise:13.0.7.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:integration_bus_for_zos:10.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:integration_bus_for_zos:10.1.0.7:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm app Connect Enterprise
Ibm integration Bus For Zos
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N'}


Subscriptions

Ibm App Connect Enterprise Integration Bus For Zos
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-20T14:26:09.238Z

Reserved: 2026-03-05T14:48:57.881Z

Link: CVE-2026-3602

cve-icon Vulnrichment

Updated: 2026-07-20T14:26:09.238Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T05:00:07Z

Weaknesses
  • CWE-73

    External Control of File Name or Path