CVE-2026-3602: IBM App Connect Enterprise and IBM Integration Bus for z/OS toolkit is vulnerable to an sql injection
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is vulnerable to SQL injection. A remote attacker could socially engineer a user into accidentally creating files they may not be aware of.
Other sources
IBM App Connect Enterprise is vulnerable to SQL injection. A remote attacker could socially engineer a user into accidentally creating files they may not be aware of.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM App Connect Enterpriseto a version that resolves this vulnerability.Fixed in 13.0.8.0Patch PH71150 - Upgrade
Upgrade
IBM App Connect Enterpriseto a version that resolves this vulnerability.Fixed in 12.0.12.27Patch PH71150 - Upgrade
Upgrade
IBM Integration Bus for z/OSto a version that resolves this vulnerability.Fixed in 10.1.0.7Patch PH71150
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3602?
CVE-2026-3602 has a medium severity rating of 5.5.
What type of vulnerability is CVE-2026-3602?
CVE-2026-3602 is an SQL injection vulnerability.
How do I fix CVE-2026-3602?
To fix CVE-2026-3602, upgrade to the latest version of IBM App Connect Enterprise or IBM Integration Bus for z/OS that addresses this vulnerability.
Who is affected by CVE-2026-3602?
IBM App Connect Enterprise versions 13.0.1.0 to 13.0.7.2 and 12.0.1.0 to 12.0.12.26, as well as IBM Integration Bus for z/OS versions 10.1.0.0 to 10.1.0.7 are affected.
What is the potential impact of CVE-2026-3602?
A successful exploit of CVE-2026-3602 could allow a remote attacker to socially engineer a user into creating files without their awareness.