CVE-2025-36133
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-09-01
Last updated on: 2025-12-18
Assigner: IBM Corporation
Description
Description
IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, andΒ 12.0 LTS: 12.0.0 through 12.0.14stores potentially sensitive information in log files during installation that could be read by a local user on the container.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.9.0 |
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.9.0 |
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.10.0 |
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.10.0 |
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.10.0 |
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.11.1 |
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.11.2 |
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.11.3 |
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.12 |
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.12 |
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.12 |
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.12 |
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.12 |
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.12 |
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.12 |
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.12 |
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.12 |
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.12 |
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.12 |
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.12 |
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.12 |
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.12 |
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.12.0 |
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.12.0 |
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.12.2 |
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.12.3 |
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.12.4 |
| ibm | app_connect_enterprise_certified_containers_operands | 12.0.12.5 |
| ibm | app_connect_enterprise_certified_containers_operands | 13.0.1.0 |
| ibm | app_connect_enterprise_certified_containers_operands | 13.0.1.0 |
| ibm | app_connect_enterprise_certified_containers_operands | 13.0.1.1 |
| ibm | app_connect_enterprise_certified_containers_operands | 13.0.2.0 |
| ibm | app_connect_enterprise_certified_containers_operands | 13.0.2.1 |
| ibm | app_connect_enterprise_certified_containers_operands | 13.0.2.2 |
| ibm | app_connect_enterprise_certified_containers_operands | 13.0.2.2 |
| ibm | app_connect_enterprise_certified_containers_operands | 13.0.3.0 |
| ibm | app_connect_enterprise_certified_containers_operands | 13.0.3.1 |
| ibm | app_connect_enterprise_certified_containers_operands | 13.0.4.0 |
| ibm | app_connect_enterprise_certified_containers_operands | 13.0.4.1 |
| ibm | app_connect_operator | From 9.2.0 (inc) to 11.6.0 (inc) |
| ibm | app_connect_operator | From 12.0.0 (inc) to 12.15.0 (exc) |
| ibm | app_connect_operator | From 12.1.0 (inc) to 12.15.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-532 | The product writes sensitive information to a log file. |