Ibm App Connect Operator vulnerabilities

4 known vulnerabilities affecting ibm/app_connect_operator.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2025-13490MEDIUMCVSS 5.9≥ 11.3.0, ≤ 11.6.0≥ 12.0.0, ≤ 12.0.20+2 more2026-03-03
CVE-2025-13490 [MEDIUM] CWE-319 CVE-2025-13490: IBM App Connect Operator versions CD 11.3.0 through 11.6.0 and 12.1.0 through 12.20.0, LTS versions IBM App Connect Operator versions CD 11.3.0 through 11.6.0 and 12.1.0 through 12.20.0, LTS versions 12.0.0 through 12.0.20, and IBM App Connect Enterprise Certified Containers Operands versions CD 12.0.11.2‑r1 through 12.0.12.5‑r1 and 13.0.1.0‑r1 through 13.0.6.1‑r1, and LTS versions 12.0.12‑r1 through 12.0.12‑r20, contain a vulnerability in which th
cvelistv5nvd
CVE-2025-36133MEDIUMCVSS 5.5≥ 9.2.0, ≤ 11.6.0≥ 12.0.0, < 12.15.0+1 more2025-09-01
CVE-2025-36133 [MEDIUM] CWE-532 CVE-2025-36133: IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 through 12.0.14stores potentially sensitive information in log files during installation that could be read by a local user on the container.
nvd
CVE-2025-1993MEDIUMCVSS 5.5≥ 8.1.0, ≤ 11.6.0≥ 12.0.0, ≤ 12.10.0+1 more2025-05-09
CVE-2025-1993 [MEDIUM] CWE-521 CVE-2025-1993: IBM App Connect Enterprise Certified Container 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2 IBM App Connect Enterprise Certified Container 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, 12.8, 12.9, and 12.10 DesignerAuthoring instances store their flows in a database that is protected by weaker than expected cryptographic algorithms that could be decrypted by a l
nvd
CVE-2024-52362MEDIUMCVSS 6.5≥ 7.2, ≤ 11.6.0≥ 12.0.0, < 12.9.0 +2 more2025-03-12
CVE-2024-52362 [MEDIUM] CWE-1286 CVE-2024-52362: IBM App Connect Enterprise Certified Container 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, IBM App Connect Enterprise Certified Container 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, and 12.8 could allow an authenticated user to cause a denial of service in the App Connect flow due to improper validation of server-side input.
nvd