IBM App Connect enterprise 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1 could allow an authenticated user to write to an arbitrary file on the system during bar configuration deployment due to improper pathname limitations on restricted directories.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7182418 |
|
History
Tue, 12 Aug 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ibm
Ibm app Connect Enterprise |
|
| CPEs | cpe:2.3:a:ibm:app_connect_enterprise:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm
Ibm app Connect Enterprise |
Thu, 06 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 06 Feb 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM App Connect enterprise 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1 could allow an authenticated user to write to an arbitrary file on the system during bar configuration deployment due to improper pathname limitations on restricted directories. | |
| Title | IBM App Connect Enterprise Arbitrary File Write | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published: 2025-02-06T00:24:40.878Z
Updated: 2025-02-22T22:16:23.189Z
Reserved: 2025-01-28T14:42:51.833Z
Link: CVE-2025-0799
Updated: 2025-02-06T15:02:57.568Z
Status : Analyzed
Published: 2025-02-06T01:15:09.580
Modified: 2025-08-12T18:46:13.900
Link: CVE-2025-0799
No data.