logo

Critical IBM API Connect Vulnerability Allows Attackers to Bypass Authentication

ID: fdd6b733-dcf8-59d0-ab6f-6333383e8062

STIX ID: report--fdd6b733-dcf8-59d0-ab6f-6333383e8062

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2025-12-30

Date Updated: 2026-04-19

Author: AnuPriya

...
...

IBM has issued an urgent advisory for a critical authentication-bypass vulnerability (CVE-2025-13915, CVSS 9.8) in API Connect that allows remote attackers to gain unauthorized access without credentials; affected versions include 10.0.8.0–10.0.8.5 and 10.0.11.0. IBM released interim fixes (iFixes) and advises immediate patching, with a temporary mitigation to disable self-service sign-up on the Developer Portal until updates are applied.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.