CVE-2025-0799
published 2025-02-06CVE-2025-0799: IBM App Connect enterprise 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1 could allow an authenticated user to write to an arbitrary file on the…
medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
IBM App Connect enterprise 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1 could allow an authenticated user to write to an arbitrary file on the system during bar configuration deployment due to improper pathname limitations on restricted directories.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | app_connect_enterprise | 12.0.1.0 – 12.0.12.10 | — |
| ibm | app_connect_enterprise | 13.0.1.0 – 13.0.2.1 | — |
| ibm | ibm_app_connect_enterprise | 12.0.1.0 – 12.0.12.10 | — |
| ibm | ibm_app_connect_enterprise | 13.0.1.0 – 13.0.2.1 | — |
| msrc | cbl2_libtiff_4.4.0-8_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_libtiff_4.5.0-1_on_cbl_mariner_1.0 | — | — |