{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2025-0799","assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","state":"PUBLISHED","assignerShortName":"ibm","dateReserved":"2025-01-28T14:42:51.833Z","datePublished":"2025-02-06T00:24:40.878Z","dateUpdated":"2025-02-22T22:16:23.189Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"IBM App Connect Enterprise","vendor":"IBM","versions":[{"lessThanOrEqual":"13.0.2.1","status":"affected","version":"13.0.1.0","versionType":"semver"},{"lessThanOrEqual":"12.0.12.10","status":"affected","version":"12.0.1.0","versionType":"semver"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<span style=\"background-color: rgb(255, 255, 255);\">IBM App Connect enterprise&nbsp;<span style=\"background-color: rgb(255, 255, 255);\">12.0.1.0 through 12.0.12.10 and</span>&nbsp;<span style=\"background-color: rgb(255, 255, 255);\">13.0.1.0 through 13.0.2.1&nbsp;</span>could allow an authenticated user to write to an arbitrary file on the system during bar configuration deployment due to improper pathname limitations on restricted directories.</span><br>"}],"value":"IBM App Connect enterprise 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1 could allow an authenticated user to write to an arbitrary file on the system during bar configuration deployment due to improper pathname limitations on restricted directories."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-22","description":"CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm","dateUpdated":"2025-02-22T22:16:23.189Z"},"references":[{"tags":["vendor-advisory"],"url":"https://www.ibm.com/support/pages/node/7182418"}],"source":{"discovery":"UNKNOWN"},"title":"IBM App Connect Enterprise Arbitrary File Write","x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-02-06T15:02:56.104075Z","id":"CVE-2025-0799","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-02-06T15:05:27.844Z"}}]}}