IBM App Connect enterprise 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1 could allow an authenticated user to write to an arbitrary file on the system during bar configuration deployment due to improper pathname limitations on restricted directories.
History

Thu, 06 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Feb 2025 00:45:00 +0000

Type Values Removed Values Added
Description IBM App Connect enterprise 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1 could allow an authenticated user to write to an arbitrary file on the system during bar configuration deployment due to improper pathname limitations on restricted directories.
Title IBM App Connect Enterprise Arbitrary File Write
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2025-02-06T00:24:40.878Z

Updated: 2025-02-22T22:16:23.189Z

Reserved: 2025-01-28T14:42:51.833Z

Link: CVE-2025-0799

cve-icon Vulnrichment

Updated: 2025-02-06T15:02:57.568Z

cve-icon NVD

Status : Received

Published: 2025-02-06T01:15:09.580

Modified: 2025-02-06T01:15:09.580

Link: CVE-2025-0799

cve-icon Redhat

No data.