CVE-2025-36133: IBM App Connect Enterprise Certified Containers Operands

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 through 12.0.14stores potentially sensitive information in log files during installation that could be read by a local user on the container.

Affected products

  • IBM App Connect Enterprise Certified Containers Operands: version 12.0.9.0 only; version 12.0.10.0 only; version 12.0.11.1 only; version 12.0.11.2 only; version 12.0.11.3 only; version 12.0.12 only; …
  • IBM App Connect Operator: from 9.2.0, up to and including 11.6.0; from 12.0.0, before 12.15.0 (fixed in 12.15.0); from 12.1.0, before 12.15.0 (fixed in 12.15.0)

Published 2025-09-01. Last modified 2026-06-17.