Impact
IBM App Connect Enterprise is vulnerable to a privilege escalation flaw that allows a remote authenticated attacker to bypass security restrictions. The weakness corresponds to a broken authorization control and can lead to unauthorized access to sensitive data or functions as CWE‑863 and is characterized by incorrect enforcement of user permissions.
Affected Systems
The vulnerability affects IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.27 and 13.0.1.0 through 13.0.8.1. Users of these releases should apply the APAR IT49854 fix, which is available in the 12.0.12.28 and 13.0.8.2 fix packs.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity for authenticated attackers who can elevate privileges. No EPSS score is provided, and the issue is not listed in the CISA KEV catalog, suggesting limited evidence of active exploitation. However, because authorization is required, the attack vector is considered remote authenticated; attackers must first obtain valid credentials to exploit the flaw. While not a zero‑day, the high impact warrants prompt remediation.
OpenCVE Enrichment