Critical Severity Vulnerability
This vulnerability has been rated as Critical severity. Immediate action is recommended.
CVE-2025-13915
CriticalVulnerability Description
IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Known Affected Software
1 configuration(s) from 1 vendor(s)
cpe:2.3:a:ibm:api_connect:10.0.11.0:*:*:*:*:*:*:*
References & Resources
Severity Details
Weakness Type (CWE)
Authentication Bypass by Primary Weakness
- Description
- The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
- Typical Severity
- Medium
- Abstraction Level
- Base
Key Information
- Published Date
- December 26, 2025
External Resources
Related News Articles
Latest news and updates about CVE-2025-13915
