CVE-2025-0799: IBM App Connect Enterprise Arbitrary File Write
IBM App Connect enterprise 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1 could allow an authenticated user to write to an arbitrary file on the system during bar configuration deployment due to improper pathname limitations on restricted directories.
Other sources
IBM App Connect enterprise could allow an authenticated user to write to an arbitrary file on the system during bar configuration deployment due to improper pathname limitations on restricted directories.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0799?
CVE-2025-0799 has a moderate severity level due to the risk of authenticated users writing to arbitrary files.
How do I fix CVE-2025-0799?
To resolve CVE-2025-0799, apply the latest patch corresponding to the affected IBM App Connect Enterprise version.
Which versions of IBM App Connect Enterprise are affected by CVE-2025-0799?
CVE-2025-0799 affects IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1.
What impact does CVE-2025-0799 have on IBM App Connect Enterprise?
CVE-2025-0799 allows authenticated users to write to arbitrary files, potentially compromising system integrity.
Is user authentication sufficient to mitigate the risk of CVE-2025-0799?
No, merely having user authentication is not sufficient as the vulnerability allows authenticated users to exploit the system.