First published: Tue Feb 04 2025(Updated: )
IBM App Connect enterprise 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1 could allow an authenticated user to write to an arbitrary file on the system during bar configuration deployment due to improper pathname limitations on restricted directories.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM App Connect | <=13.0.1.0 - 13.0.2.1 | |
IBM App Connect | <=12.0.1.0 - 12.0.12.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0799 has a moderate severity level due to the risk of authenticated users writing to arbitrary files.
To resolve CVE-2025-0799, apply the latest patch corresponding to the affected IBM App Connect Enterprise version.
CVE-2025-0799 affects IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1.
CVE-2025-0799 allows authenticated users to write to arbitrary files, potentially compromising system integrity.
No, merely having user authentication is not sufficient as the vulnerability allows authenticated users to exploit the system.