CVE-2025-1993 Details
Description
IBM App Connect Enterprise Certified Container 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, 12.8, 12.9, and 12.10 DesignerAuthoring instances store their flows in a database that is protected by weaker than expected cryptographic algorithms that could be decrypted by a local user.
A vulnerability exists in IBM App Connect Enterprise Certified Container versions 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, 12.8, 12.9, and 12.10. The DesignerAuthoring instances in these versions store their flows in a database that is secured with cryptographic algorithms weaker than expected, potentially allowing a local user to decrypt the data.
Users are advised to upgrade to IBM App Connect Enterprise Certified Container Operator version 12.11.0 or higher, and ensure that all DesignerAuthoring components are at 13.0.3.0-r1 or higher. For versions 12.0 LTS, upgrade to version 12.0.11 or higher, and ensure all DesignerAuthoring components are at 12.0.12-r11 or higher.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 9, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7233054 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-521 | Weak Password Requirements | [email protected] |
| CWE-521 | Weak Password Requirements | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm app connect enterprise certified containers operands | 12.0.7.0 r4 12.0.11.1 r1 12.0.11.2 r1 12.0.11.3 r1 12.0.12 r1 12.0.12 r10 12.0.12.0 r1 12.0.12.0 r2 12.0.12.2 r1 12.0.12.3 r1 12.0.12.4 r1 12.0.12.5 r1 13.0.1.0 r1 13.0.1.0 r2 13.0.1.1 r1 13.0.2.0 r1 13.0.2.1 r1 13.0.2.2 r1 13.0.2.2 r2 |
CPE
Remediation
| |
| ibm app connect operator | >= 8.1.0, <= 11.6.0 >= 12.0.0, <= 12.10.0 >= 12.1.0, <= 12.10.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 20, 2025 | Initial Analysis | [email protected] |
| May 9, 2025 | New CVE Received | [email protected] |