IBM has identified three critical vulnerabilities in its products, all rated CVSS 9.8. These vulnerabilities affect App Connect Enterprise, Power HMC, and webMethods Integration, allowing unauthenticated attackers to execute arbitrary commands or code. While there are currently no reported exploits in the wild, the vulnerabilities pose significant risks to organizations. Affected product versions and mitigation strategies are provided, recommending immediate patching.
The specific vulnerabilities include command injection in Power HMC, deserialization RCE in webMethods, and a path traversal flaw in App Connect Enterprise.