IBM has released urgent security updates for a critical vulnerability in IBM API Connect that allows remote attackers to bypass authentication and access sensitive data. This flaw, CVE-2025-13915, affects multiple versions of the platform and is considered highly severe with a CVSS score of 9.8. #CVE-2025-13915 #IBMAPIConnect
Keypoints
- The vulnerability enables remote attackers to bypass authentication controls in affected IBM API Connect versions.
- It is classified as CWE-305: Authentication Bypass by Primary Weakness, highlighting enforcement failure for authentication mechanisms.
- IBM has issued interim fixes for versions V10.0.8.0 through V10.0.8.5 and V10.0.11.0 to mitigate the risk.
- Organizations are urged to upgrade to secure versions immediately and disable self-service sign-up as a temporary workaround.
- The flawβs exploitation could lead to complete system compromise, exposing sensitive data and backend services.
Read More: https://thecyberexpress.com/ibm-api-connect-security-vulnerability/