IBM has urged its customers to install security updates for a critical authentication bypass vulnerability in its API Connect, which could allow attackers to gain remote access to applications.
See also: IBM QRadar SIEM: Vulnerability allows unauthorized actions

API Connect is a gateway for application programming interfaces (APIs), enabling organizations to develop, test, and manage APIs, providing controlled access to internal services for applications, partners, and external developers.
Available on-premises, in the cloud, or in hybrid environments, it is used by hundreds of companies in the banking, healthcare, retail, and telecommunications sectors. The vulnerability is tracked as CVE-2025-13915 and is rated 9.8/10 severity, affecting IBM API Connect versions 10.0.11.0 and 10.0.8.0 through 10.0.8.5 .
Successful exploitation of the vulnerability allows unauthorized users to gain remote access to exposed applications by bypassing authentication, through low-sophistication attacks that do not require user interaction.
IBM asked administrators to upgrade vulnerable installations to the latest version to prevent potential attacks and provided temporary protections for those who cannot immediately apply the update.
See also: IBM: Cost of data breach in the US is rising

"IBM API Connect could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application. IBM strongly recommends that you immediately address the vulnerability by upgrading," the company said. "Customers who are unable to install the interim fix should disable self-service user registration in the Developer Portal, if enabled, to reduce their exposure to this vulnerability."
Detailed instructions for applying the CVE-2025-13915 patch to VMware, OCP, and Kubernetes environments are available in this support document.
Over the past four years, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added multiple IBM security vulnerabilities to its list of known exploitable vulnerabilities, marking them as actively exploited and directing federal agencies to secure their systems, per Business Commitment Directive (BOD) 22-01.
See also: SIEM vulnerabilities in IBM QRadar allow execution of arbitrary commands

Two of these vulnerabilities, a code execution flaw in IBM Aspera Faspex (CVE-2022-47986) and an invalid input flaw in IBM InfoSphere BigInsights (CVE-2013-3993), have also been flagged by the US cybersecurity agency as being exploited in ransomware attacks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
