CVE-2025-36133
Severity CVSS v4.0:
Pending analysis
Type:
CWE-532
Information Exposure Through Log Files
Publication date:
01/09/2025
Last modified:
18/12/2025
Description
IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 through 12.0.14stores potentially sensitive information in log files during installation that could be read by a local user on the container.
Impact
Base Score 3.x
5.90
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ibm:app_connect_enterprise_certified_containers_operands:12.0.9.0:r2:*:*:continuous_delivery:*:*:* | ||
| cpe:2.3:a:ibm:app_connect_enterprise_certified_containers_operands:12.0.9.0:r3:*:*:continuous_delivery:*:*:* | ||
| cpe:2.3:a:ibm:app_connect_enterprise_certified_containers_operands:12.0.10.0:r1:*:*:continuous_delivery:*:*:* | ||
| cpe:2.3:a:ibm:app_connect_enterprise_certified_containers_operands:12.0.10.0:r2:*:*:continuous_delivery:*:*:* | ||
| cpe:2.3:a:ibm:app_connect_enterprise_certified_containers_operands:12.0.10.0:r3:*:*:continuous_delivery:*:*:* | ||
| cpe:2.3:a:ibm:app_connect_enterprise_certified_containers_operands:12.0.11.1:r1:*:*:continuous_delivery:*:*:* | ||
| cpe:2.3:a:ibm:app_connect_enterprise_certified_containers_operands:12.0.11.2:r1:*:*:continuous_delivery:*:*:* | ||
| cpe:2.3:a:ibm:app_connect_enterprise_certified_containers_operands:12.0.11.3:r1:*:*:continuous_delivery:*:*:* | ||
| cpe:2.3:a:ibm:app_connect_enterprise_certified_containers_operands:12.0.12:r1:*:*:lts:*:*:* | ||
| cpe:2.3:a:ibm:app_connect_enterprise_certified_containers_operands:12.0.12:r10:*:*:lts:*:*:* | ||
| cpe:2.3:a:ibm:app_connect_enterprise_certified_containers_operands:12.0.12:r11:*:*:lts:*:*:* | ||
| cpe:2.3:a:ibm:app_connect_enterprise_certified_containers_operands:12.0.12:r12:*:*:lts:*:*:* | ||
| cpe:2.3:a:ibm:app_connect_enterprise_certified_containers_operands:12.0.12:r13:*:*:lts:*:*:* | ||
| cpe:2.3:a:ibm:app_connect_enterprise_certified_containers_operands:12.0.12:r14:*:*:lts:*:*:* | ||
| cpe:2.3:a:ibm:app_connect_enterprise_certified_containers_operands:12.0.12:r2:*:*:lts:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



