VYPR
Medium severity5.5NVD Advisory· Published May 27, 2026· Updated May 27, 2026

CVE-2026-5515

CVE-2026-5515

Description

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log files that could be read by a local user.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.0 with WS-Security and Java 17 logs sensitive information accessible to local users.

Vulnerability

IBM App Connect Enterprise versions 13.0.1.0 through 13.0.7.0, when using WS-Security with Java 17, stores potentially sensitive information in log files. The vulnerability exists because the application does not properly sanitize sensitive data before writing it to logs. This issue is specifically triggered when the WS-Security feature is enabled and Java 17 is used as the runtime environment [1].

Exploitation

An attacker must have local access to the system running the affected IBM App Connect Enterprise instance. No special privileges beyond the ability to read log files on the local file system are required. The attacker can read the log files where sensitive information (such as credentials or other confidential data) may have been written during normal operation of the WS-Security functionality [1].

Impact

Successful exploitation leads to disclosure of sensitive information (confidentiality impact). The CVSS v3.1 base score is 5.5 (Medium) with vector AV:L/AC:L/PR:L/S:U/C:H/I:N/A:N, indicating high confidentiality impact, no integrity or availability impact [1]. The attacker gains access to potentially credential or other sensitive data contained in the logs.

Mitigation

IBM has released the fix via APAR IT49227, available in IBM App Connect Enterprise Fix Pack Release 13.0.7.1. Users should upgrade to version 13.0.7.1 or later. No workarounds are provided by the vendor [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.