Categories: Cyber Security News

Critical IBM API Connect Vulnerability Let Attackers Bypass Logins

A critical security alert regarding a severe vulnerability in the IBM API Connect platform that could allow remote attackers to bypass authentication mechanisms.

Discovered during internal testing, the flaw poses a significant risk to organizations relying on the platform for API management. It grants unauthorized actors access to the application without requiring valid credentials.

The vulnerability, tracked as CVE-2025-13915, has been assigned a critical CVSS base score of 9.8 out of 10. This near-maximum score reflects the ease of exploitation and the high impact on confidentiality, integrity, and availability.

The flaw is classified under CWE-305, which refers to an “Authentication Bypass by Primary Weakness.” According to the advisory, the issue allows a remote attacker to circumvent the login process entirely.

Because the attack vector is network-based (AV: N) and requires no special privileges (PR: N) or user interaction (UI: N), the risk of automated or widespread exploitation is high.

The vulnerability impacts specific versions of IBM API Connect. Administrators are urged to check their deployments for the following versions:

Product Affected Versions
IBM API Connect V10.0.8 Versions 10.0.8.0 through 10.0.8.5
IBM API Connect V10.0.11 Version 10.0.11.0

IBM strongly recommends that all affected customers upgrade immediately to the patched versions. The company has released iFixes for the affected release ranges.

Sponsored
Product Version Fix Availability
IBM API Connect V10.0.8 Patches available for versions 10.0.8.1 through 10.0.8.5
IBM API Connect V10.0.11 iFix available for version 10.0.11

For organizations that cannot immediately apply the patch, IBM has provided a temporary mitigation. Administrators should disable self-service sign-up on their Developer Portal if it is currently enabled.

While this does not fix the underlying code flaw, it helps minimize the attack surface and reduces exposure to this specific vulnerability until the permanent fix can be deployed.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

The post Critical IBM API Connect Vulnerability Let Attackers Bypass Logins appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

Bungie Reveals Marathon Premium Currency, LUX, Promises It Can’t Be Used to Buy Gameplay Advantages

Bungie has finally revealed Marathon’s premium currency, called LUX, while promising it can’t be used…

1 minute ago

Castlevania: Belmont’s Curse Is ‘Not a Roguelike or a Roguelite Game,’ Konami Insists

Castlevania: Belmont's Curse — announced at Sony's State of Play showcase last month as part…

2 minutes ago

GOP bill would require Tennessee public schools to check student immigration status

A crowd of protesters boos House Majority Leader William Lamberth during a Wednesday committee meeting…

6 minutes ago

US Senate rejects limits on Trump war powers, as Hegseth vows ‘death and destruction’ for Iran

Senate Minority Leader Chuck Schumer, D-N.Y., speaks with reporters during a press conference in the…

6 minutes ago

Ahead of race for Senate Speaker, three Republicans hold almost $1 million each in campaign cash

Sen. Bo Watson, in bow tie, is expected to be a leading contender to succeed…

6 minutes ago

Taxpayer dollars flood pregnancy centers. Oversight hasn’t followed.

Crisis pregnancy centers have been the beneficiary of at least a half-billion dollars since the…

7 minutes ago

This website uses cookies.