IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is vulnerable to SQL injection. A remote attacker could socially engineer a user into accidentally creating files they may not be aware of.
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:NIBM App Connect Enterprise
APPIbm12.0.1.0 – 12.0.12.27 (excl.)13.0.1.0 – 13.0.8.0 (excl.)IBM Integration Bus
APPIbm10.1.0.0 – 10.1.0.7IBM Z\/os
OSIbmall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
Related vulnerabilities
CVE-2026-14525CRITICAL9.4same product
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty ...
CVE-2026-11707CRITICAL9.3PL ✓same product
XSS w konsoli administracyjnej IBM Tivoli System Automation Application Manager 4.1
CVE-2026-15435CRITICAL9.8PL ✓same product
Path Traversal w IBM App Connect Enterprise umożliwiający zapis dowolnych plików
CVE-2025-36038CRITICAL9.0PL ✓same product
RCE w IBM WebSphere Application Server przez niebezpieczną deserializację
CVE-2024-22317CRITICAL9.1PL ✓same product
IBM App Connect Enterprise — brak limitu prób uwierzytelnienia (DoS/ujawnienie danych)