IBM App Connect enterprise 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1 could allow an authenticated user to write to an arbitrary file on the system during bar configuration deployment due to improper pathname limitations on restricted directories.
References
Link | Resource |
---|---|
https://www.ibm.com/support/pages/node/7182418 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
12 Aug 2025, 18:46
Type | Values Removed | Values Added |
---|---|---|
First Time |
Ibm app Connect Enterprise
Ibm |
|
Summary |
|
|
CPE | cpe:2.3:a:ibm:app_connect_enterprise:*:*:*:*:*:*:*:* | |
References | () https://www.ibm.com/support/pages/node/7182418 - Vendor Advisory |
06 Feb 2025, 01:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-06 01:15
Updated : 2025-08-12 18:46
NVD link : CVE-2025-0799
Mitre link : CVE-2025-0799
CVE.ORG link : CVE-2025-0799
JSON object : View
Products Affected
ibm
- app_connect_enterprise
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')