Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2025-13915— Authentication bypass in IBM API Connect

CVSS 9.8 · Critical EPSS 0.30% · P53
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-13915

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Authentication bypass in IBM API Connect
Source: NVD (National Vulnerability Database)
Vulnerability Description
IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
使用基本弱点进行的认证绕过
Source: NVD (National Vulnerability Database)
Vulnerability Title
IBM API Connect 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
IBM API Connect(APIConnect)是美国国际商业机器(IBM)公司的一套用于管理API生命周期的集成解决方案。该产品支持创建、运行、管理和保护API和微服务等。 IBM API Connect 10.0.8.0版本至10.0.8.5版本和10.0.11.0版本存在安全漏洞,该漏洞源于可绕过身份验证机制,可能导致未经授权的访问。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
IBMAPI Connect 10.0.8.0 ~ 10.0.8.5 cpe:2.3:a:ibm:api_connect:10.0.8.0:*:*:*:*:*:*:*

II. Public POCs for CVE-2025-13915

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-13915

登录查看更多情报信息。

Vendor Advisories for CVE-2025-13915 (1)

Same Patch Batch · IBM · 2025-12-26 · 9 CVEs total

CVE-2025-127717.8 HIGHIBM Concert Software Improper Restriction of Operations within the Bounds of a Memory Buff
CVE-2025-646457.7 HIGHMultiple Vulnerabilities in IBM Concert Software.
CVE-2025-361926.7 MEDIUMMissing Authorization with the DS8900F and DS8A00 Hardware Management Console
CVE-2025-17215.9 MEDIUMBM Concert Software Improper Clearing of Heap Memory Before Release.
CVE-2025-362305.4 MEDIUMXSS in IBM Aspera Faspex
CVE-2025-146874.3 MEDIUMClient-Side Enforcement of Server-Side Security in IBM Db2 Intelligence Center
CVE-2025-362283.8 LOWIncorrect Execution-Assigned Permissions in IBM Aspera Faspex
CVE-2025-362293.1 LOWExposure of Sensitive System Information to an Unauthorized Control Sphere in IBM Aspera F

IV. Related Vulnerabilities

V. Comments for CVE-2025-13915

No comments yet


Leave a comment