Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3045 articles · 183981 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-15435PATCHED
ibm · app connect enterpri

IBM App Connect Enterprise is vulnerable to arbitrary file write vulnerability

Description

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.

Affected Products

VendorProductVersions
ibmapp connect enterpri13.0.1.0, 12.0.1.0

References

  • https://www.ibm.com/support/pages/node/7281896(vendor-advisory, patch)

Related News (2 articles)

Tier D
Heise Security5d ago
IBM App Connect Enterprise: Angreifer können Daten manipulieren
→ No new info (linked only)
Tier C
VulDB5d ago
CVE-2026-15435 | IBM App Connect Enterprise up to 12.0.12.27/13.0.7.2 path traversal
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://www.ibm.com/support/pages/node/7281896
CWECWE-22
PublishedJul 30, 2026
Trending Score32
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-9198EXPKEV
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
Trending: 146
CRITICALCVE-2026-14446
IBM WebSphere Application Server is affected by a privilege escalation
Trending: 35
CRITICALCVE-2026-14512
IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information
Trending: 35
CRITICALCVE-2026-14529
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a server-side request forgery
Trending: 33
HIGHCVE-2026-15280
IBM WebSphere Application Server Liberty is affected by a remote code execution and path-segment injection vulnerability
Trending: 30

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 30, 2026
Discovered by ZDM
Jul 30, 2026
Patch Available
Jul 31, 2026