IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user to perform unauthorized actions on customer defined resources due to missing authorization.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7249061 |
|
History
Sat, 25 Oct 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 |
Fri, 24 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user to perform unauthorized actions on customer defined resources due to missing authorization. | |
| Title | IBM App Connect Enterprise runtime is vulnerable to a lack of authorization on windows environments using IWA | |
| First Time appeared |
Ibm
Ibm app Connect Enterprise |
|
| CPEs | cpe:2.3:a:ibm:app_connect_enterprise:12.0.1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:app_connect_enterprise:12.0.12.17:*:*:*:*:*:*:* cpe:2.3:a:ibm:app_connect_enterprise:13.0.1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:app_connect_enterprise:13.0.4.2:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm app Connect Enterprise |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published: 2025-10-24T09:35:20.590Z
Updated: 2025-10-25T02:03:18.631Z
Reserved: 2025-04-15T21:16:55.331Z
Link: CVE-2025-36361
Updated: 2025-10-24T13:19:12.854Z
Status : Received
Published: 2025-10-24T10:15:38.670
Modified: 2025-10-25T02:15:39.550
Link: CVE-2025-36361
No data.