← Back

CVE-2025-0799

nvd nist
Published: Feb 6, 2025Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: psirt@us.ibm.com (Secondary)

Description

IBM App Connect enterprise 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1 could allow an authenticated user to write to an arbitrary file on the system during bar configuration deployment due to improper pathname limitations on restricted directories.

Affected (2)

1 product
App Connect Enterprise
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
From 12.0.1.0 to 12.0.12.10
From 13.0.1.0 to 13.0.2.1

References (1)

Source: psirt@us.ibm.com
Vendor Advisory

Timeline

No history available yet.