logo

IBM warns of critical API Connect auth bypass vulnerability

ID: ded5ce63-34a5-5f25-8ec5-8f2e9c44e44a

STIX ID: report--ded5ce63-34a5-5f25-8ec5-8f2e9c44e44a

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-12-31

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

IBM disclosed a critical authentication-bypass vulnerability (CVE-2025-13915, CVSS 9.8) affecting IBM API Connect versions 10.0.11.0 and 10.0.8.0–10.0.8.5 that could allow unauthenticated attackers to remotely access exposed applications; IBM urges immediate patching or temporary mitigations (such as disabling self-service sign-up) and published patching instructions for various deployment environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.