Severity
6.5MEDIUM
EPSS
0.0%
top 89.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 8

Description

IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF005 and 24.0.1 through 24.0.1 IF002 could allow an authenticated user to view sensitive user and system information due to an indirect object reference through a user-controlled key.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/cloud_pak_for_business_automation24.0.024.0.0 IF005+1
NVDibm/cloud_pak24.0.0, 24.0.1+1

🔴Vulnerability Details

2
GHSA
GHSA-9fwv-9wqg-4pm8: IBM Cloud Pak for Business Automation 242025-08-08
CVEList
IBM Cloud Pak for Business Automation security bypass2025-08-08

📋Vendor Advisories

1
Microsoft
Julia Lawall reported this null pointer dereference this should fix it.2024-05-14
CVE-2025-36023 (MEDIUM CVSS 6.5) | IBM Cloud Pak for Business Automati | cvebase.io