CVE-2026-81832: IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 SAP Adapter is vulnerable to an XML external entity (XXE) attack.
Other sources
IBM App Connect Enterprise SAP Adapter is vulnerable to an XML external entity (XXE) attack
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM App Connect Enterpriseto a version that resolves this vulnerability.Fixed in 12.0.12.29Patch IT49773 - Upgrade
Upgrade
IBM App Connect Enterpriseto a version that resolves this vulnerability.Fixed in 13.0.8.2Patch IT49773 - Upgrade
Upgrade
IBM Integration Bus for z/OSto a version that resolves this vulnerability.Fixed in 10.1.0.7Patch IT49773
Event History
Frequently Asked Questions
Which deployments are affected?
Affected versions are IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, IBM App Connect Enterprise 12.0.1.0 through 12.0.12.28, and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 when using the SAP Adapter.
What level of access does an attacker need?
The vector indicates network-reachable exploitation with low attack complexity. The attacker must have low-level privileges, and no user interaction is required.
What is the potential impact?
Successful exploitation may expose highly sensitive information. The supplied vector indicates no direct integrity or availability impact, while scope may extend beyond the vulnerable component.