CVE-2025-36361

IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user to perform unauthorized actions on customer defined resources due to missing authorization.
References
Link Resource
https://www.ibm.com/support/pages/node/7249061 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:app_connect_enterprise:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:app_connect_enterprise:*:*:*:*:*:*:*:*

History

28 Oct 2025, 14:27

Type Values Removed Values Added
First Time Ibm
Ibm app Connect Enterprise
CPE cpe:2.3:a:ibm:app_connect_enterprise:*:*:*:*:*:*:*:*
References () https://www.ibm.com/support/pages/node/7249061 - () https://www.ibm.com/support/pages/node/7249061 - Vendor Advisory

27 Oct 2025, 13:20

Type Values Removed Values Added
Summary
  • (es) IBM App Connect Enterprise 13.0.1.0 hasta 13.0.4.2, y 12.0.1.0 hasta 12.0.12.17 podría permitir a un usuario autenticado realizar acciones no autorizadas en recursos definidos por el cliente debido a la falta de autorización.

25 Oct 2025, 02:15

Type Values Removed Values Added
CWE CWE-862

24 Oct 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-24 10:15

Updated : 2025-10-28 14:27


NVD link : CVE-2025-36361

Mitre link : CVE-2025-36361

CVE.ORG link : CVE-2025-36361


JSON object : View

Products Affected

ibm

  • app_connect_enterprise
CWE
CWE-862

Missing Authorization