IBM Integration Bus For Zos
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in IBM Integration Bus For Zos.
By the Year
In 2026 there have been 10 vulnerabilities in IBM Integration Bus For Zos with an average score of 5.7 out of ten. Last year, in 2025 Integration Bus For Zos had 1 security vulnerability published. That is, 9 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 2.50
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 10 | 5.70 |
| 2025 | 1 | 8.20 |
It may take a day or so for new Integration Bus For Zos vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent IBM Integration Bus For Zos Security Vulnerabilities
IBM App Connect Enterprise 13.x DoS via XML Entity Validation (CVE-2026-16180)
CVE-2026-16180
5.7 - Medium
- September 04, 2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 Toolkit could allow an authenticated user to cause a denial-of-service condition due to improper validation of XML entities.
XEE
IBM App Connect Enterprise 12/13.0.x: Local Credential Exposure via Logging
CVE-2026-16689
6.2 - Medium
- September 04, 2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of credentials.
Insertion of Sensitive Information into Log File
IBM App Connect 12/13 & Integration Bus z/OS: Recursion DoS (13.0.8.1)
CVE-2026-17440
5.5 - Medium
- September 04, 2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to cause a denial of service due to uncontrolled recursion.
Stack Exhaustion
IBM App Connect Enterprise 13.x Trace Log Credential Leakage (Cleartext)
CVE-2026-17442
5.1 - Medium
- September 04, 2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to credentials being written to trace logs in cleartext.
Insertion of Sensitive Information into Log File
IBM App Connect Enterprise XXE (v13.x, v12.x, z/OS 10.1.x)
CVE-2026-17443
5.3 - Medium
- September 04, 2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw.
XXE
IBM App Connect Enterprise XXE Info Leak 13.0.1.0-13.0.8.1
CVE-2026-17444
5.3 - Medium
- September 04, 2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.
XXE
IBM App Connect E 12/13: Local Info Disclosure via Improper DB Cred Logging
CVE-2026-19649
6.2 - Medium
- September 04, 2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of database credentials.
Insertion of Sensitive Information into Log File
IBM App Connect Entp 13.0.8.1 DoS via Infinite Loop
CVE-2026-78543
5.3 - Medium
- September 04, 2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote attacker to cause a denial of service due to an infinite loop.
Infinite Loop
XXE in IBM App Connect Enterprise SAP Adapter 12.0.x-13.0.8.1
CVE-2026-81832
7.7 - High
- September 04, 2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 SAP Adapter is vulnerable to an XML external entity (XXE) attack.
XXE
IBM App Connect Enterprise / Integration Bus SQLi in v12-13 (13.0.7.2)
CVE-2026-3602
4.7 - Medium
- June 30, 2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is vulnerable to SQL injection. A remote attacker could socially engineer a user into accidentally creating files they may not be aware of.
External Control of File Name or Path
IBM Integration Bus 10.1.0.0-10.1.0.5 Code Injection via privileged install dir
CVE-2025-36014
8.2 - High
- July 07, 2025
IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.5 is vulnerable to code injection by a privileged user with access to the IIB install directory.
Code Injection
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for IBM Integration Bus For Zos or by IBM? Click the Watch button to subscribe.