MEDIUM
IBM App Connect Enterprise information disclosure
Published Sep 1, 2025
5.9
MEDIUMCVSS 3.1
EPSS 0.11%
Description
IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 through 12.0.14stores potentially sensitive information in log files during installation that could be read by a local user on the container.
Affected products
-
Affected
- ≥ 12.0.0, ≤ 12.0.14
- ≥ 12.1.0, ≤ 12.14.0
- ≥ 9.2.0, ≤ 11.6.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| IBM | App Connect Enterprise Certified Container | unaffected | Affected
|
OR
- 12.0.9.0
- 12.0.9.0
- 12.0.10.0
- 12.0.10.0
- 12.0.10.0
- 12.0.11.1
- 12.0.11.2
- 12.0.11.3
- 12.0.12
- 12.0.12
- 12.0.12
- 12.0.12
- 12.0.12
- 12.0.12
- 12.0.12
- 12.0.12
- 12.0.12
- 12.0.12
- 12.0.12
- 12.0.12
- 12.0.12
- 12.0.12
- 12.0.12.0
- 12.0.12.0
- 12.0.12.2
- 12.0.12.3
- 12.0.12.4
- 12.0.12.5
- 13.0.1.0
- 13.0.1.0
- 13.0.1.1
- 13.0.2.0
- 13.0.2.1
- 13.0.2.2
- 13.0.2.2
- 13.0.3.0
- 13.0.3.1
- 13.0.4.0
- 13.0.4.1
- ≥ 9.2.0 · ≤ 11.6.0
- ≥ 12.0.0 · < 12.15.0
- ≥ 12.1.0 · < 12.15.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-26340 Advisory
- https://www.ibm.com/support/pages/node/7243690 vendor-advisorypatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-26340 | Advisory | |
| https://www.ibm.com/support/pages/node/7243690 | vendor-advisorypatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Sep 1, 2025
Updated Sep 2, 2025
Reserved Apr 15, 2025
Link CVE-2025-36133
CISA Vulnrichment
Updated Sep 2, 2025
Red Hat
No data
GitHub
No data