CVE-2025-1838

Severity
6.5MEDIUM
EPSS
0.2%
top 56.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 3

Description

IBM Cloud Pak for Business Automation 24.0.0 and 24.0.1 through 24.0.1 IF001 Authoring allows an authenticated user to bypass client-side data validation in an authoring user interface which could cause a denial of service.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/cloud_pak_for_business_automation24.0.124.0.1 IF001+1
NVDibm/cloud_pak24.0.0, 24.0.1+1

🔴Vulnerability Details

2
GHSA
GHSA-w4rj-x734-wm94: IBM Cloud Pak for Business Automation 242025-05-03
CVEList
IBM Cloud Pak for Business Automation denial of service2025-05-03

📋Vendor Advisories

1
Microsoft
A use-after-free flaw was found in vhost_net_set_backend in drivers/vhost/net.c in virtio network subcomponent in the Linux kernel due to a double fget. This flaw could allow a local attacker to crash2023-04-11