ZeroHour

CVE-2026-81832

moderate

XXE in IBM App Connect Enterprise and Integration Bus for z/OS SAP Adapter

CVSS 3.1
7.7 high
EPSS
<1%p20
Published
()
Modified
AI analysis

IBM App Connect Enterprise (13.0.1.0 through 13.0.8.1 and 12.0.1.0 through 12.0.12.28) and the SAP Adapter of IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 are vulnerable to an XML external entity (XXE) injection flaw (CWE-611) in XML processing. An authenticated, low-privilege user (CVSS PR:L) who can supply crafted XML to affected parsing — such as message flows using the SAP Adapter that process untrusted XML documents or entity references — can cause the parser to resolve external entities. The CVSS vector shows scope change with high confidentiality impact and no integrity or availability impact, meaning an attacker's realistic gain is reading local files from the integration node and reaching internal network services (SSRF), not code execution or data modification. Any organization running the affected releases of App Connect Enterprise or the Integration Bus for z/OS SAP Adapter is affected. Exploitation is not currently known: there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.

What to do: Check IBM's security bulletin for CVE-2026-81832 and upgrade App Connect Enterprise to releases beyond 13.0.8.1 (13.x) and 12.0.12.28 (12.x), and apply IBM's fix for the Integration Bus for z/OS 10.1 SAP Adapter as specified in the advisory. Until patched, limit SAP Adapter flows to trusted XML sources and disable external entity/DOCTYPE resolution in XML parsing where the configuration supports it. Inventory integration nodes for use of the SAP Adapter and identify which run the affected version ranges to prioritize patching.

Affected
IBM App Connect Enterprise13.0.1.0 through 13.0.8.1
IBM App Connect Enterprise12.0.1.0 through 12.0.12.28
IBM Integration Bus for z/OS (SAP Adapter)10.1.0.0 through 10.1.0.7
Estimated exposure
moderate≈1,000–10,000 enterprise deployments (subset of the ACE/IIB install base using the SAP Adapter); exact exposed count unknown — IBM integration middleware is widely deployed inside large enterprises rather than exposed on the public internet, and the affected component is narrowed to the SAP Adapter, so the estimate reflects a modest slice of the ACE/IIB installed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 SAP Adapter is vulnerable to an XML external entity (XXE) attack.

Vendors
ibm
Products
app connect enterprise, integration bus for z\/os
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.