CVE-2025-13490Cleartext Transmission of Sensitive Info in IBM APP Connect Enterprisecertified Containers Operands

Severity
5.9MEDIUMNVD
EPSS
0.0%
top 95.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 3

Description

IBM App Connect Operator versions CD 11.3.0 through 11.6.0 and 12.1.0 through 12.20.0, LTS versions 12.0.0 through 12.0.20, and IBM App Connect Enterprise Certified Containers Operands versions CD 12.0.11.2‑r1 through 12.0.12.5‑r1 and 13.0.1.0‑r1 through 13.0.6.1‑r1, and LTS versions 12.0.12‑r1 through 12.0.12‑r20, contain a vulnerability in which the IBM App Connect Enterprise Certified Container transmits data in clear text, potentially allowing an attacker to intercept and obtain sensitive in

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages4 packages

CVEListV5ibm/app_connect_enterprisecertified_containers_operandsCD:12.0.11.2r1 - 12.0.12.5-r1, 13.0.1.0-r1 - 13.0.6.1-r112.0 LTS:12.0.12-r1 - 12.0.12-r20
CVEListV5ibm/app_connect_operatorCD:11.3.011.6.0, 12.1.0 - 12.20.112.0 LTS:12.0.0 - 12.0.20
NVDibm/app_connect_operator11.3.011.6.0+2

🔴Vulnerability Details

2
CVEList
IBM App Connect Enterprise Certified Container IntegrationServer and IntegrationRuntime operands that report metrics are vulnerable to loss of confidentiality2026-03-03
GHSA
GHSA-h4v8-qw7g-35xj: IBM App Connect Operator versions CD 112026-03-03
CVE-2025-13490 — IBM vulnerability | cvebase