IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HIBM App Connect Enterprise
APPIbm12.0.1.0 – 12.0.12.28 (excl.)13.0.1.0 – 13.0.8.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References
Related vulnerabilities
CVE-2024-22317CRITICAL9.1PL ✓same product
IBM App Connect Enterprise — brak limitu prób uwierzytelnienia (DoS/ujawnienie danych)
CVE-2026-14522HIGH8.8PL ✓same product
IBM App Connect Enterprise — command injection przez znaki CRLF
CVE-2026-12947HIGH7.5PL ✓same product
IBM App Connect Enterprise – ujawnienie wrażliwych danych w plikach logów
CVE-2026-14519HIGH7.5PL ✓same product
IBM App Connect Enterprise — path traversal umożliwia odczyt dowolnych plików
CVE-2026-3602MEDIUM4.7same product
IBM App Connect Enterprise w wersjach 13.0.1.0 do 13.0.7.2, 12.0.1.0 do 12.0.12.26 oraz IBM Integration Bus fo...