CVE-2026-12947
Undergoing Analysis Undergoing Analysis - In Progress

IBM App Connect Enterprise Information Disclosure Vulnerability

Vulnerability report for CVE-2026-12947, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: IBM Corporation

Description

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores potentially sensitive information in log files that could be read by a local user.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ibm app_connect_enterprise From 13.0.1.0 (inc) to 13.0.7.2 (inc)
ibm app_connect_enterprise From 12.0.1.0 (inc) to 12.0.12.27 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves IBM App Connect Enterprise storing potentially sensitive information in log files. A local user with access to these logs could read the sensitive data, leading to unauthorized information disclosure.

Detection Guidance

Check IBM App Connect Enterprise log files for sensitive information exposure. Review logs in default directories like /var/log/ibm/ace or installation paths for entries containing credentials or configuration details.

Impact Analysis

If you use IBM App Connect Enterprise versions 13.0.1.0 through 13.0.7.2 or 12.0.1.0 through 12.0.12.27, an attacker with local access could exploit this to view sensitive information stored in log files, potentially leading to data breaches or compliance violations.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate GDPR (data protection) and HIPAA (health information privacy) requirements. Organizations must ensure logs are protected to maintain compliance.

Mitigation Strategies

Restrict log file permissions to prevent unauthorized access. Configure log rotation to limit sensitive data retention. Update IBM App Connect Enterprise to the latest patched version if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12947. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart