CVE-2025-1993: IBM App Connect Enterprise Certified Container information disclosure
IBM App Connect Enterprise Certified Container 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, 12.8, 12.9, and 12.10 DesignerAuthoring instances store their flows in a database that is protected by weaker than expected cryptographic algorithms that could be decrypted by a local user.
Other sources
IBM App Connect Enterprise Certified Container DesignerAuthoring instances store their flows in a database that is protected by weaker than expected cryptographic algorithms that could be decrypted by a local user.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1993?
CVE-2025-1993 has a high severity rating due to the potential for unauthorized access to sensitive data.
How do I fix CVE-2025-1993?
To fix CVE-2025-1993, update your IBM App Connect Enterprise Certified Container to the latest version that addresses this vulnerability.
What versions of IBM products are affected by CVE-2025-1993?
CVE-2025-1993 affects IBM App Connect Enterprise Certified Container versions from 8.1 to 12.10 and related products within specific version ranges.
What are the potential impacts of CVE-2025-1993?
The potential impacts of CVE-2025-1993 include exposure of sensitive flow data and possible unauthorized access to the database.
How can I assess if CVE-2025-1993 impacts my system?
To assess if CVE-2025-1993 impacts your system, check the versions of your IBM App Connect products against the known affected versions.