IBM App Connect Enterprise Critical Vulnerabilities
Summary
CERT-Bund has issued a security advisory regarding critical vulnerabilities in IBM App Connect Enterprise versions prior to 11.6.0, 12.21.0, and 12.0.22. The vulnerabilities, with a CVSS base score of 9.8, could allow attackers to manipulate files, cause denial of service, execute arbitrary code, or perform cross-site scripting attacks.
What changed
CERT-Bund has released a security advisory (WID-SEC-2026-0895) detailing critical vulnerabilities affecting IBM App Connect Enterprise. The vulnerabilities, rated with a CVSS base score of 9.8, allow for remote attacks including file manipulation, denial of service, arbitrary code execution, and cross-site scripting. Affected versions include IBM App Connect Enterprise <11.6.0, <12.21.0, and LTS <12.0.22, running on Linux, UNIX, and Windows operating systems.
Organizations using vulnerable versions of IBM App Connect Enterprise must apply available mitigations immediately to address these critical security risks. Failure to do so could result in severe system compromise, including unauthorized code execution and data manipulation. The advisory indicates that mitigations are available, and users should consult IBM's security advisories for specific patching and remediation steps.
What to do next
- Apply available mitigations for IBM App Connect Enterprise
- Update to patched versions of IBM App Connect Enterprise
Source document (simplified)
[WID-SEC-2026-0895] IBM App Connect Enterprise: Mehrere Schwachstellen CVSS Base Score 9.8 (kritisch) CVSS Temporal Score 8.5 (hoch) Remoteangriff ja Datum 26.03.2026 Stand 27.03.2026 Mitigation ja
Betroffene Systeme
Betriebssystem
- Linux
- Sonstiges
- UNIX
- Windows
Produktbeschreibung
IBM App Connect Enterprise kombiniert die branchenbewährten Technologien des IBM Integration Bus mit Cloud-nativen Technologien.
Produkte
26.03.2026
- IBM App Connect Enterprise <11.6.0
IBM App Connect Enterprise <12.21.0
IBM App Connect Enterprise LTS <12.0.22
Angriff
Angriff
Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Dateien zu manipulieren, um einen Denial of Service Angriff durchzuführen, um beliebigen Programmcode auszuführen, und um einen Cross-Site Scripting Angriff durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Related changes
Source
Classification
Who this affects
Taxonomy
Browse Categories
Get Data Privacy & Cybersecurity alerts
Weekly digest. AI-summarized, no noise.
Free. Unsubscribe anytime.
Get alerts for this source
We'll email you when CERT-Bund Security Advisories publishes new changes.