IBM App Connect Enterprise Toolkit can leak data
Important security updates have been released for IBM App Connect Enterprise Toolkit, InfoSphere and WebSphere.
(Image: Alfa Photo/Shutterstock.com)
For security reasons, administrators of IBM applications should install the latest updates. If this is not done, attackers can attack systems and execute malicious code, among other things. So far, there are no reports of ongoing attacks.
Security patches available
The most dangerous is a vulnerability (CVE-2025-4949 “critical”) in the Eclipse JGit component of IBM App Connect Enterprise Toolkit and Integration Bus for z/OS Toolkit. Errors can occur if XML files prepared by attackers are processed. If such an attack succeeds, data may be leaked or DoS states may occur. The developers claim to have solved the security problem in v13 Fix Pack Release 13.0.5.0.
A malicious code vulnerability (CVE-2025-36245 “high”) threatens InfoSphere Information Server. However, an attacker must be authenticated for this. If this is the case, they can execute their commands.
The remaining vulnerabilities are categorized as “medium” threat level. Attackers can use these vulnerabilities to paralyze WebSphere Application Server via a DoS attack, for example. Admins can find further information on the vulnerabilities and security updates in the linked alerts.
Videos by heise
Most recently, IBM's developers closed DoS gaps in the data analysis platform SPSS Analytic Server.
List sorted by threat level in descending order:
- IBM App Connect Enterprise Toolkit and IBM Integration Bus for z/OS Toolkit are vulnerable to Improper Restriction of XML External Entity Reference due to Eclipse JGit (CVE-2025-4949)
- IBM InfoSphere Information Server is vulnerable to execution of arbitrary commands (CVE-2025-36245)
- IBM InfoSphere Information Server is affected by a vulnerability in Apache Wink (CVE-2010-2245)
- IBM InfoSphere Information Server is affected by multiple vulnerabilities in the urllib3 library
- IBM InfoSphere Information Server is affected by a vulnerability in Connect2id Nimbus JOSE + JWT (CVE-2025-53864)
- IBM InfoSphere Information Server is affected by an improper input validation vulnerability in Apache POI (CVE-2025-31672)
- IBM InfoSphere Information Server is affected by a vulnerability in Apache XML Graphics FOP (CVE-2024-28168)
- IBM WebSphere Application Server is affected by a denial of service (CVE-2025-36099)
(des)