Impact
The vulnerability is an XML External Entity (XXE) flaw in the SAP Adapter of IBM App Connect Enterprise and IBM Integration Bus for z/OS. An attacker who can supply crafted XML can retrieve arbitrary files from the host system, trigger server‑side requests and otherwise influence how the adapter processes XML documents. This flaw can lead to confidentiality and integrity compromises, and may affect the availability of services that handle the XML.
Affected Systems
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, IBM App Connect Enterprise 12.0.1.0 through 12.0.12.28, and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 are affected.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV, suggesting no publicly known exploitation yet. The likely attack vector is remote, via network exposure of the SAP Adapter to untrusted XML sources, enabling an attacker to deliver malicious XML payloads and exploit the XXE weakness.
OpenCVE Enrichment