ZeroHour

CVE-2026-78543

large

Unauthenticated infinite loop DoS in IBM App Connect Enterprise and Integration Bus

CVSS 3.1
7.5 high
EPSS
<1%p32
Published
()
Modified
AI analysis

IBM App Connect Enterprise and IBM Integration Bus for z/OS contain a denial-of-service flaw (CWE-835, infinite loop) in which network input can drive the software into an endless processing loop. A remote, unauthenticated attacker with network reachability to an affected integration node can trigger the loop with low-complexity requests (the advisory does not name a specific protocol or endpoint), consuming CPU until the service is restarted. The impact is availability only — no data disclosure or tampering — but successful attacks can take down message flows and the business integrations that depend on them. Organizations running ACE 13.0.1.0–13.0.8.1, ACE 12.0.1.0–12.0.12.28, or Integration Bus for z/OS 10.1.0.0–10.1.0.7 are affected. There is currently no public proof of concept, no KEV listing, and a low EPSS score (0.4%), indicating no known exploitation in the wild.

What to do: Upgrade App Connect Enterprise and Integration Bus for z/OS to a fix level beyond the affected ranges using the fix packs listed in IBM's security bulletin for your stream (13.0.x, 12.0.x, and 10.1 for z/OS); the bulletin's fix list gives the exact fixed versions. Until patched, restrict network access to integration node and HTTP listener ports and monitor integration servers for sustained high CPU, which may indicate a looping process. No exploitation is known, so internal systems can follow normal patch cycles, but prioritize any instance reachable from untrusted networks.

Affected
IBM App Connect Enterprise13.0.1.0 through 13.0.8.1
IBM App Connect Enterprise12.0.1.0 through 12.0.12.28
IBM Integration Bus for z/OS10.1.0.0 through 10.1.0.7
Estimated exposure
largetens of thousands of deployed instances worldwide (est.), with only a small fraction directly internet-exposed — App Connect Enterprise (successor to IBM Integration Bus / Message Broker) is mainstream enterprise integration middleware widely used in banking, insurance, telecom and government environments, implying a global installed base in the tens…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote attacker to cause a denial of service due to an infinite loop.

Vendors
ibm
Products
app connect enterprise, integration bus for z\/os
Weakness
CWE-835
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.