CVE-2026-17442: IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to credentials being written to trace logs in cleartext.
Other sources
IBM App Connect Enterprise could allow a local attacker to obtain sensitive information due to credentials being written to trace logs in cleartext.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM App Connect Enterpriseto a version that resolves this vulnerability.Fixed in 12.0.12.29Patch IT49773 - Upgrade
Upgrade
IBM App Connect Enterpriseto a version that resolves this vulnerability.Fixed in 13.0.8.2Patch IT49773 - Upgrade
Upgrade
IBM Integration Bus for z/OSto a version that resolves this vulnerability.Fixed in 10.1.0.7Patch IT49773
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs local access to an affected IBM App Connect Enterprise or IBM Integration Bus for z/OS environment and access to trace logs containing credentials.
What information could be exposed?
Credentials may be written to trace logs in cleartext, allowing a local attacker who can read those logs to obtain sensitive information.
What should teams review while assessing exposure?
Review trace logs for cleartext credentials and identify which local users, service accounts, or operational processes can access those logs. Treat any credentials found in accessible logs as potentially exposed.