cbcvebase.
CVE-2025-36054
published 2025-11-06

CVE-2025-36054: IBM Business Automation Workflow containers 24.0.0 through 24.0.0-IF006, 24.0.1 through 24.0.1-IF004, 25.0.0 through 25.0.0-IF001 and IBM Business Automation…

PriorityP429medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.20%
9.8th percentile
IBM Business Automation Workflow containers 24.0.0 through 24.0.0-IF006, 24.0.1 through 24.0.1-IF004, 25.0.0 through 25.0.0-IF001 and IBM Business Automation Workflow traditional with Process Federation Server 24.0.0 through 24.0.1 and 25.0.0 are vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Affected

11 ranges
VendorProductVersion rangeFixed in
ibmbusiness_automation_workflow——
ibmbusiness_automation_workflow——
ibmbusiness_automation_workflow——
ibmbusiness_automation_workflow_containers24.0.0 – 24.0.0-IF006—
ibmbusiness_automation_workflow_containers24.0.1 – 24.0.1-IF004—
ibmbusiness_automation_workflow_containers25.0.0 – 25.0.0-IF001—
ibmbusiness_automation_workflow_traditional_with_process_federation_server——
ibmbusiness_automation_workflow_traditional_with_process_federation_server24.0.0 – 24.0.1—
ibmprocess_federation_server——
ibmprocess_federation_server——
ibmprocess_federation_server——
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.