CVE-2025-1993: IBM App Connect Enterprise Certified Containers Operands

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

IBM App Connect Enterprise Certified Container 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, 12.8, 12.9, and 12.10 DesignerAuthoring instances store their flows in a database that is protected by weaker than expected cryptographic algorithms that could be decrypted by a local user.

Affected products

  • IBM App Connect Enterprise Certified Containers Operands: version 12.0.7.0 only; version 12.0.11.1 only; version 12.0.11.2 only; version 12.0.11.3 only; version 12.0.12 only; version 12.0.12.0 only; …
  • IBM App Connect Operator: from 8.1.0, up to and including 11.6.0; from 12.0.0, up to and including 12.10.0; from 12.1.0, up to and including 12.10.0

Published 2025-05-09. Last modified 2026-06-17.