CVE-2026-15435
EUVD-2026-5113830.07.2026, 15:16
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| ibm | connect\ | 13.0.1.0 ≤ 𝑥 ≤ 13.0.7.2 | CNA |
| ibm | connect\ | 12.0.1.0 ≤ 𝑥 ≤ 12.0.12.27 | CNA |
Vulnerability Media Exposure