CVE Vulnerabilities

CVE-2025-36133

Insertion of Sensitive Information into Log File

Published: Sep 01, 2025 | Modified: Dec 18, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 through 12.0.14stores potentially sensitive information in log files during installation that could be read by a local user on the container.

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
App_connect_enterprise_certified_containers_operandsIbm12.0.9.0-r2 (including)12.0.9.0-r2 (including)
App_connect_enterprise_certified_containers_operandsIbm12.0.9.0-r3 (including)12.0.9.0-r3 (including)
App_connect_enterprise_certified_containers_operandsIbm12.0.10.0-r1 (including)12.0.10.0-r1 (including)
App_connect_enterprise_certified_containers_operandsIbm12.0.10.0-r2 (including)12.0.10.0-r2 (including)
App_connect_enterprise_certified_containers_operandsIbm12.0.10.0-r3 (including)12.0.10.0-r3 (including)
App_connect_enterprise_certified_containers_operandsIbm12.0.11.1-r1 (including)12.0.11.1-r1 (including)
App_connect_enterprise_certified_containers_operandsIbm12.0.11.2-r1 (including)12.0.11.2-r1 (including)
App_connect_enterprise_certified_containers_operandsIbm12.0.11.3-r1 (including)12.0.11.3-r1 (including)
App_connect_enterprise_certified_containers_operandsIbm12.0.12-r1 (including)12.0.12-r1 (including)
App_connect_enterprise_certified_containers_operandsIbm12.0.12-r10 (including)12.0.12-r10 (including)
App_connect_enterprise_certified_containers_operandsIbm12.0.12-r11 (including)12.0.12-r11 (including)
App_connect_enterprise_certified_containers_operandsIbm12.0.12-r12 (including)12.0.12-r12 (including)
App_connect_enterprise_certified_containers_operandsIbm12.0.12-r13 (including)12.0.12-r13 (including)
App_connect_enterprise_certified_containers_operandsIbm12.0.12-r14 (including)12.0.12-r14 (including)
App_connect_enterprise_certified_containers_operandsIbm12.0.12-r2 (including)12.0.12-r2 (including)
App_connect_enterprise_certified_containers_operandsIbm12.0.12-r3 (including)12.0.12-r3 (including)
App_connect_enterprise_certified_containers_operandsIbm12.0.12-r4 (including)12.0.12-r4 (including)
App_connect_enterprise_certified_containers_operandsIbm12.0.12-r5 (including)12.0.12-r5 (including)
App_connect_enterprise_certified_containers_operandsIbm12.0.12-r6 (including)12.0.12-r6 (including)
App_connect_enterprise_certified_containers_operandsIbm12.0.12-r7 (including)12.0.12-r7 (including)
App_connect_enterprise_certified_containers_operandsIbm12.0.12-r8 (including)12.0.12-r8 (including)
App_connect_enterprise_certified_containers_operandsIbm12.0.12-r9 (including)12.0.12-r9 (including)
App_connect_enterprise_certified_containers_operandsIbm12.0.12.0-r1 (including)12.0.12.0-r1 (including)
App_connect_enterprise_certified_containers_operandsIbm12.0.12.0-r2 (including)12.0.12.0-r2 (including)
App_connect_enterprise_certified_containers_operandsIbm12.0.12.2-r1 (including)12.0.12.2-r1 (including)
App_connect_enterprise_certified_containers_operandsIbm12.0.12.3-r1 (including)12.0.12.3-r1 (including)
App_connect_enterprise_certified_containers_operandsIbm12.0.12.4-r1 (including)12.0.12.4-r1 (including)
App_connect_enterprise_certified_containers_operandsIbm12.0.12.5-r1 (including)12.0.12.5-r1 (including)
App_connect_enterprise_certified_containers_operandsIbm13.0.1.0-r1 (including)13.0.1.0-r1 (including)
App_connect_enterprise_certified_containers_operandsIbm13.0.1.0-r2 (including)13.0.1.0-r2 (including)
App_connect_enterprise_certified_containers_operandsIbm13.0.1.1-r1 (including)13.0.1.1-r1 (including)
App_connect_enterprise_certified_containers_operandsIbm13.0.2.0-r1 (including)13.0.2.0-r1 (including)
App_connect_enterprise_certified_containers_operandsIbm13.0.2.1-r1 (including)13.0.2.1-r1 (including)
App_connect_enterprise_certified_containers_operandsIbm13.0.2.2-r1 (including)13.0.2.2-r1 (including)
App_connect_enterprise_certified_containers_operandsIbm13.0.2.2-r2 (including)13.0.2.2-r2 (including)
App_connect_enterprise_certified_containers_operandsIbm13.0.3.0-r1 (including)13.0.3.0-r1 (including)
App_connect_enterprise_certified_containers_operandsIbm13.0.3.1-r1 (including)13.0.3.1-r1 (including)
App_connect_enterprise_certified_containers_operandsIbm13.0.4.0-r1 (including)13.0.4.0-r1 (including)
App_connect_enterprise_certified_containers_operandsIbm13.0.4.1-r1 (including)13.0.4.1-r1 (including)
App_connect_operatorIbm9.2.0 (including)11.6.0 (including)
App_connect_operatorIbm12.0.0 (including)12.15.0 (excluding)
App_connect_operatorIbm12.1.0 (including)12.15.0 (excluding)

Potential Mitigations

References