CVE-2026-3602 PUBLISHED

IBM App Connect Enterprise and IBM Integration Bus for z/OS toolkit is vulnerable to an sql injection

Assigner: ibm
Reserved: 05.03.2026 Published: 30.06.2026 Updated: 30.06.2026

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is vulnerable to SQL injection. A remote attacker could socially engineer a user into accidentally creating files they may not be aware of.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS Score: 4.7

Product Status

Vendor IBM
Product App Connect Enterprise
Versions
  • affected from 13.0.1.0 to 13.0.7.2 (incl.)
  • affected from 12.0.1.0 to 12.0.12.26 (incl.)
Vendor IBM
Product Integration Bus for z/OS
Versions
  • affected from 10.1.0.0 to 10.1.0.7 (incl.)

Solutions

IBM strongly recommends addressing the vulnerability/vulnerabilities now by applying the appropriate fix to IBM App Connect Enterprise and IBM Integration Bus for z/OS Affected Product(s)Version(s)APARRemediation / FixesIBM App Connect Enterprise13.0.1.0 - 13.0.7.2PH71150The APAR (PH71150) is available fromIBM App Connect Enterprise v13- Fix Pack Release 13.0.8.0IBM App Connect Enterprise12.0.1.0 - 12.0.12.26 PH71150The APAR (PH71150) is available fromIBM App Connect Enterprise v12- Fix Pack Release 12.0.12.27IBM Integration Bus for z/OS10.1.0.0 - 10.1.0.7PH71150Interim Fix for APAR (PH71150) is available to apply to 10.1.0.7 from IBM Fix Central

References

Problem Types

  • CWE-73 External Control of File Name or Path CWE