CVE-2025-36092

CWE-12843 documents3 sources
Severity
6.5MEDIUM
EPSS
0.1%
top 76.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 3

Description

IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause a denial of service due to the improper validation of input length.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/cloud_pak_for_business_automation24.0.0, 24.0.1, 25.0.0+2
NVDibm/cloud_pak24.0.0, 24.0.1, 25.0.0+2

🔴Vulnerability Details

2
GHSA
GHSA-p635-chcg-qxpc: IBM Cloud Pak For Business Automation 252025-11-03
CVEList
IBM Business Automation Insights improper input validation2025-11-03