Impact
An infinite loop can be triggered from a remote request, allowing an attacker to consume CPU resources and cause a denial of service in IBM App Connect Enterprise and IBM Integration Bus for z/OS. The weakness is classified as CWE‑835, an uncontrolled or infinite loop. Once triggered, the affected adapter nodes become unresponsive, potentially disrupting mission‑critical integration flows and applications that depend on them.
Affected Systems
Affected vendors include IBM, specifically IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.28 and 13.0.1.0 through 13.0.8.1, and IBM Integration Bus for z/OS version 10.1.0.0 through 10.1.0.7.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. No EPSS score is provided, implying limited known exploitation data. Because it is not listed in the CISA KEV catalog, there is no evidence of widespread active exploitation yet. The likely attack vector is the remote delivery of crafted input to the adapter node, causing resource exhaustion and service interruption.
OpenCVE Enrichment