← Back

CVE-2025-1993

nvd nist
Published: May 9, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

IBM App Connect Enterprise Certified Container 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, 12.8, 12.9, and 12.10 DesignerAuthoring instances store their flows in a database that is protected by weaker than expected cryptographic algorithms that could be decrypted by a local user.

Affected (22)

2 products
Configuration A
22 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version 12.0.11.1 r1
Version 12.0.11.2 r1
Version 12.0.11.3 r1
Version 12.0.12.0 r1
Version 12.0.12.0 r2
Version 12.0.12.2 r1
Version 12.0.12.3 r1
Version 12.0.12.4 r1
Version 12.0.12.5 r1
Version 12.0.12 r10
Version 12.0.12 r1
Version 12.0.7.0 r4
Version 13.0.1.0 r1
Version 13.0.1.0 r2
Version 13.0.1.1 r1
Version 13.0.2.0 r1
Version 13.0.2.1 r1
Version 13.0.2.2 r1
Version 13.0.2.2 r2
Ibm
From 12.1.0 to 12.10.0
From 8.1.0 to 11.6.0
From 12.0.0 to 12.10.0

References (1)

Source: psirt@us.ibm.com
Vendor Advisory

Timeline

No history available yet.