Impact
The vulnerability allows a remote attacker to inject arbitrary SQL statements into the toolkit’s database queries through its interface, enabling reading, modification, or deletion of data in the connected databases. The engineering attack could also cause a user to unknowingly create potentially malicious files, indicating that the injection may be triggered through user interactions.
Affected Systems
IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.26 and 13.0.1.0 through 13.0.7.2, and IBM Integration Bus for z/OS versions 10.1.0.0 through 10.1.0.7.
Risk and Exploitability
The CVSS score of 4.7 places this issue in the Moderate severity range. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. A remote attacker can exploit the flaw by sending crafted input to the toolkit’s interface; socially engineered users may also be prompted to create files that exploit the injection.
OpenCVE Enrichment