Critical IBM API Connect Vulnerability Enables Authentication Bypass

Critical IBM API Connect Vulnerability Enables Authentication Bypass

IBM has released urgent security updates for a critical vulnerability in IBM API Connect that allows remote attackers to bypass authentication and access sensitive data. This flaw, CVE-2025-13915, affects multiple versions of the platform and is considered highly severe with a CVSS score of 9.8. #CVE-2025-13915 #IBMAPIConnect

Keypoints

  • The vulnerability enables remote attackers to bypass authentication controls in affected IBM API Connect versions.
  • It is classified as CWE-305: Authentication Bypass by Primary Weakness, highlighting enforcement failure for authentication mechanisms.
  • IBM has issued interim fixes for versions V10.0.8.0 through V10.0.8.5 and V10.0.11.0 to mitigate the risk.
  • Organizations are urged to upgrade to secure versions immediately and disable self-service sign-up as a temporary workaround.
  • The flaw’s exploitation could lead to complete system compromise, exposing sensitive data and backend services.

Read More: https://thecyberexpress.com/ibm-api-connect-security-vulnerability/