Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 373 respecto a la semana anterior
Críticas / altas1323▲ 43 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
51 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.8) | 0.14% | — | IBM APP Connect EnterpriseAI | 14/9/2026 | 16/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization. | |
| Pendiente de análisis | Alta (7.8) | 0.14% | — | IBM APP Connect EnterpriseAI | 14/9/2026 | 16/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization. | |
| Pendiente de análisis | Alta (7.8) | 0.15% | — | IBM APP Connect EnterpriseAI | 14/9/2026 | 16/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (8.8) | 0.50% | — | IBM APP Connect Enterprise | 10/9/2026 | 16/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.27 could allow a remote authenticated attacker to bypass security restrictions due to incorrect authorization. | |
| Analizada | Media (6.5) | 0.29% | — | IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os | 4/9/2026 | 10/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection. | |
| Analizada | Media (6.5) | 0.29% | — | IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os | 4/9/2026 | 9/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw. | |
| Analizada | Media (5.5) | 0.09% | — | IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os | 4/9/2026 | 10/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to credentials being written to trace logs in cleartext. | |
| Analizada | Media (5.5) | 0.10% | — | IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os | 4/9/2026 | 9/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to cause a denial of service due to uncontrolled recursion. | |
| Analizada | Media (5.5) | 0.11% | — | IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os | 4/9/2026 | 8/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of credentials. | |
| Analizada | Media (5.7) | 0.22% | — | IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os | 4/9/2026 | 9/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 Toolkit could allow an authenticated user to cause a denial-of-service condition due to improper validation of XML entities. | |
| Analizada | Alta (7.5) | 0.55% | — | IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os | 4/9/2026 | 9/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote attacker to cause a denial of service due to an infinite loop. | |
| Analizada | Media (5.5) | 0.11% | — | IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os | 4/9/2026 | 9/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of database credentials. | |
| Analizada | Alta (7.7) | 0.38% | — | IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os | 4/9/2026 | 8/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 SAP Adapter is vulnerable to an XML external entity (XXE) attack. | |
| Analizada | Crítica (9.8) | 0.73% | — | IBM APP Connect Enterprise | 30/7/2026 | 5/8/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system. | |
| Analizada | Crítica (9.8) | 1.0% | — | IBM APP Connect Enterprise | 30/7/2026 | 5/8/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due to improper neutralization of CRLF characters. | |
| Analizada | Alta (7.5) | 0.62% | — | IBM APP Connect Enterprise | 30/7/2026 | 5/8/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to read arbitrary files due to a path traversal vulnerability. | |
| Analizada | Alta (7.5) | 0.40% | — | IBM APP Connect Enterprise | 30/7/2026 | 5/8/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores potentially sensitive information in log files that could be read by a local user. | |
| Modificada | Media (5.5) | 0.27% | — | IBM APP Connect EnterpriseIBM Integration BUS | 30/6/2026 | 20/7/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is vulnerable to SQL injection. A remote attacker could socially engineer a user into accidentally creating files they may not be aware of. | |
| Modificada | Media (5.5) | 0.14% | — | IBM APP Connect Enterprise | 27/5/2026 | 17/6/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log files that could be read by a local user. | |
| Modificada | Media (5.9) | 0.19% | — | IBM APP Connect Enterprise Certified Containers OperandsIBM APP Connect Operator | 3/3/2026 | 17/6/2026 | IBM App Connect Operator versions CD 11.3.0 through 11.6.0 and 12.1.0 through 12.20.0, LTS versions 12.0.0 through 12.0.20, and IBM App Connect Enterprise Certified Containers Operands versions CD 12.0.11.2‑r1 through 12.0.12.5‑r1 and 13.0.1.0‑r1 through 13.0.6.1‑r1, and LTS versions 12.0.12‑r1 through 12.0.12‑r20,… | |
| Aplazada | Media (5.1) | 0.17% | — | IBM APP Connect EnterpriseAI | 5/2/2026 | 17/6/2026 | IBM App Connect Enterprise Certified Container CD: 11.2.0 through 11.6.0, 12.1.0 through 12.19.0 and 12.0 LTS: 12.0.0 through 12.0.19 could allow an attacker to access sensitive files or modify configurations due to an untrusted search path. | |
| Analizada | Alta (8.8) | 0.22% | — | IBM APP Connect Enterprise | 24/10/2025 | 17/6/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user to perform unauthorized actions on customer defined resources due to missing authorization. | |
| Analizada | Media (5.5) | 0.11% | — | IBM APP Connect Enterprise Certified Containers OperandsIBM APP Connect Operator | 1/9/2025 | 17/6/2026 | IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 through 12.0.14stores potentially sensitive information in log files during installation that could be read by a local user on the container. | |
| Analizada | Media (5.5) | 0.13% | — | IBM APP Connect Enterprise Certified Containers OperandsIBM APP Connect Operator | 9/5/2025 | 17/6/2026 | IBM App Connect Enterprise Certified Container 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, 12.8, 12.9, and 12.10 DesignerAuthoring instances store their flows in a database that is protected by weaker than expected cryptographic… | |
| Analizada | Media (6.5) | 0.47% | — | IBM APP Connect Enterprise Certified Containers OperandsIBM APP Connect Operator | 12/3/2025 | 17/6/2026 | IBM App Connect Enterprise Certified Container 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, and 12.8 could allow an authenticated user to cause a denial of service in the App Connect flow due to improper validation of… |