CVE-2025-36133
MEDIUMDescription
IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 through 12.0.14stores potentially sensitive information in log files during installation that could be read by a local user on the container.
Is your site exposed to CVE-2025-36133?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_enterprise_certified_containers_operands |
| ibm | app_connect_operator |
| ibm | app_connect_operator |
| ibm | app_connect_operator |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-36133? +
How severe is CVE-2025-36133? +
What products are affected by CVE-2025-36133? +
How do I check if I'm vulnerable to CVE-2025-36133? +
Related Vulnerabilities
An issue was discovered in the PaperCut Hive Ricoh embedded application. When the "Deep Logging" (diagnostic) mode is enabled, the …
In some circumstances, debug artifacts uploaded by the CodeQL Action after a failed code scanning workflow run may contain the …
kube-audit-rest is a simple logger of mutation/creation requests to the k8s api. If the "full-elastic-stack" example vector configuration was used …
A vulnerability exists in Docker Desktop prior to version 4.39.0 that could lead to the unintentional disclosure of sensitive information …
Buildx is a Docker CLI plugin that extends build capabilities using BuildKit. Cache backends support credentials by setting secrets directly …
Metabase is an open source Business Intelligence and Embedded Analytics tool. When admins change Snowflake connection details in Metabase (either …