CVE-2025-0799 – IBM App Connect Enterprise Path Traversal Vulnerability

The following table lists the changes that have been made to the
CVE-2025-0799 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Feb. 06, 2025

    Action Type Old Value New Value
    Added Description IBM App Connect enterprise 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1 could allow an authenticated user to write to an arbitrary file on the system during bar configuration deployment due to improper pathname limitations on restricted directories.
    Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
    Added CWE CWE-22
    Added Reference https://www.ibm.com/support/pages/node/7182418
Share the Post:

Related Posts