CVE-2026-17440: IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to cause a denial of service due to uncontrolled recursion.
Other sources
IBM App Connect Enterprise could allow a local attacker to cause a denial of service due to uncontrolled recursion.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM App Connect Enterpriseto a version that resolves this vulnerability.Fixed in 12.0.12.29Patch IT49773 - Upgrade
Upgrade
IBM App Connect Enterpriseto a version that resolves this vulnerability.Fixed in 13.0.8.2Patch IT49773 - Upgrade
Upgrade
IBM Integration Bus for z/OSto a version that resolves this vulnerability.Patch IT49773
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The issue is described as exploitable by a local attacker. The available information does not indicate remote exploitation.
Which IBM products are identified as affected?
IBM App Connect Enterprise and IBM Integration Bus for z/OS are listed.