IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an attacker to access unauthorized content or perform unauthorized actions using man in the middle techniques due to improper access controls.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7249999 |
|
History
Mon, 03 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Nov 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an attacker to access unauthorized content or perform unauthorized actions using man in the middle techniques due to improper access controls. | |
| Title | security vulnerabilities are addressed with IBM Business Automation Insights iFixes for October 2025. | |
| First Time appeared |
Ibm
Ibm cloud Pak For Business Automation |
|
| Weaknesses | CWE-602 | |
| CPEs | cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_for_business_automation:25.0.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm cloud Pak For Business Automation |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published: 2025-11-03T15:54:30.869Z
Updated: 2025-11-03T16:25:26.455Z
Reserved: 2025-04-15T21:16:14.711Z
Link: CVE-2025-36093
Updated: 2025-11-03T16:25:20.905Z
Status : Awaiting Analysis
Published: 2025-11-03T16:15:34.763
Modified: 2025-11-04T15:41:31.450
Link: CVE-2025-36093
No data.