CVE-2026-12947: IBM App Connect Enterprise is vulnerable to Confidentiality disclosure on Discovery Connector nodes
IBM App Connect Enterprise
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM App Connect Enterpriseto a version that resolves this vulnerability.Fixed in 12.0.12.28Patch IT49670 - Upgrade
Upgrade
IBM App Connect Enterpriseto a version that resolves this vulnerability.Fixed in 13.0.8.0Patch IT49670
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12947?
The severity of CVE-2026-12947 is rated high with a score of 7.5.
What systems are affected by CVE-2026-12947?
IBM App Connect Enterprise versions 13.0.1.0 through 13.0.7.2 and 12.0.1.0 through 12.0.12.27 are affected by CVE-2026-12947.
What type of vulnerability is CVE-2026-12947?
CVE-2026-12947 is a confidentiality disclosure vulnerability on Discovery Connector nodes.
How do I fix CVE-2026-12947?
To mitigate CVE-2026-12947, apply the latest patches or updates provided by IBM for the affected App Connect Enterprise versions.
What information is disclosed in CVE-2026-12947?
CVE-2026-12947 potentially discloses sensitive information stored in log files that can be accessed by local users.