CVE-2025-0799: IBM App Connect Enterprise

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

IBM App Connect enterprise 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1 could allow an authenticated user to write to an arbitrary file on the system during bar configuration deployment due to improper pathname limitations on restricted directories.

Affected products

  • IBM App Connect Enterprise: from 12.0.1.0, up to and including 12.0.12.10; from 13.0.1.0, up to and including 13.0.2.1

Published 2025-02-06. Last modified 2026-06-17.