CVE-2026-19649 PUBLISHED

IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs

Assigner: ibm
Reserved: 12.08.2026 Published: 04.09.2026 Updated: 04.09.2026

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of database credentials.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 6.2

Product Status

Vendor IBM
Product App Connect Enterprise
Versions
  • affected from 13.0.1.0 to 13.0.8.1 (incl.)
  • affected from 12.0.1.0 to 12.0.12.28 (incl.)
Vendor IBM
Product Integration Bus for z/OS
Versions
  • affected from 10.1.0.0 to 10.1.0.7 (incl.)

Solutions

IBM strongly recommends addressing the vulnerability/vulnerabilities now by applying the appropriate fix to IBM App Connect Enterprise and IBM Integration Bus for z/OS

Affected Product(s)Version(s)APAR

Remediation / Fixes

IBM App Connect Enterprise13.0.1.0 - 13.0.8.1IT49773

The APAR (IT49773) is available from 

IBM App Connect Enterprise v13- Fix Pack Release 13.0.8.2 https://www.ibm.com/support/pages/node/7285177

IBM App Connect Enterprise12.0.1.0 - 12.0.12.28IT49773

The APAR (IT49773) is available from 

IBM App Connect Enterprise v12- Fix Pack Release 12.0.12.29 https://www.ibm.com/support/pages/node/7284253

IBM Integration Bus for z/OS10.1.0.0 - 10.1.0.7IT49773

Interim Fix for APAR (IT49773) is available to apply to 10.1.0.7 from

IBM Fix Central https://www.ibm.com/support/fixcentral/swg/selectFixes

References

Problem Types

  • CWE-532 Insertion of Sensitive Information into Log File CWE