CVE-2025-13490: IBM App Connect Enterprise Certified Container IntegrationServer and IntegrationRuntime operands that report metrics are vulnerable to loss of confidentiality
IBM App Connect Enterprise Certified Container transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
Other sources
IBM App Connect Operator versions CD 11.3.0 through 11.6.0 and 12.1.0 through 12.20.0, LTS versions 12.0.0 through 12.0.20, and IBM App Connect Enterprise Certified Containers Operands versions CD 12.0.11.2‑r1 through 12.0.12.5‑r1 and 13.0.1.0‑r1 through 13.0.6.1‑r1, and LTS versions 12.0.12‑r1 through 12.0.12‑r20, contain a vulnerability in which the IBM App Connect Enterprise Certified Container transmits data in clear text, potentially allowing an attacker to intercept and obtain sensitive information through man‑in‑the‑middle techniques.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13490?
CVE-2025-13490 is considered a high severity vulnerability due to the potential for loss of confidentiality of sensitive information.
How do I fix CVE-2025-13490?
To fix CVE-2025-13490, update to the latest version of the IBM App Connect Enterprise Certified Container or App Connect Operator that addresses this vulnerability.
What are the affected versions in CVE-2025-13490?
CVE-2025-13490 affects IBM App Connect Operator versions between 11.3.0 and 11.6.0, and several versions of the IBM App Connect Enterprise Certified Containers Operands.
What kind of data is at risk in CVE-2025-13490?
CVE-2025-13490 could allow attackers to obtain sensitive information transmitted in clear text.
How can I ensure I am not vulnerable to CVE-2025-13490?
To ensure you are not vulnerable to CVE-2025-13490, verify your IBM App Connect installations are running the patched versions released by IBM.