CVE-2025-13915: Authentication bypass in IBM API Connect
IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.
Other sources
IBM API Connect could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13915?
CVE-2025-13915 has a critical severity rating due to its potential for unauthorized access to the IBM API Connect application.
How do I fix CVE-2025-13915?
To fix CVE-2025-13915, upgrade IBM API Connect to versions 10.0.8.6 or later, or 10.0.11.1 or later.
What types of attacks does CVE-2025-13915 enable?
CVE-2025-13915 enables remote attackers to bypass authentication mechanisms.
Which versions of IBM API Connect are affected by CVE-2025-13915?
IBM API Connect versions from 10.0.8.0 to 10.0.8.5 and 10.0.11.0 are affected by CVE-2025-13915.
Can CVE-2025-13915 be exploited remotely?
Yes, CVE-2025-13915 can be exploited remotely, allowing unauthorized access.