Ibm Business Automation Workflow Containers vulnerabilities

4 known vulnerabilities affecting ibm/business_automation_workflow_containers.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2025-13096HIGHCVSS 7.1≥ V25.0.0, ≤ V25.0.0-IF002≥ V24.0.1, ≤ V24.0.1-IF005+1 more2026-02-02
CVE-2025-13096 [HIGH] CWE-918 CVE-2025-13096: IBM Business Automation Workflow containers V25.0.0 through V25.0.0-IF007, V24.0.1 - V24.0.1-IF007, IBM Business Automation Workflow containers V25.0.0 through V25.0.0-IF007, V24.0.1 - V24.0.1-IF007, V24.0.0 - V24.0.0-IF007 and IBM Business Automation Workflow traditional V25.0.0, V24.0.1, V24.0.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensi
cvelistv5nvd
CVE-2025-36058MEDIUMCVSS 5.5≥ 25.0.0, ≤ 25.0.0 Interim Fix 002≥ 24.0.1, ≤ 24.0.1 Interim Fix 005+1 more2026-01-20
CVE-2025-36058 [MEDIUM] CWE-538 CVE-2025-36058: IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24 IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 006. IBM Cloud Pak for Business Automation and IBM Business Automation Workflow containers may disclose sensitve configuration information in a config map.
cvelistv5nvd
CVE-2025-36059MEDIUMCVSS 5.5≥ 25.0.0, ≤ 25.0.0 Interim Fix 002≥ 24.0.1, ≤ 24.0.1 Interim Fix 005+1 more2026-01-20
CVE-2025-36059 [MEDIUM] CWE-250 CVE-2025-36059: IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24 IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 006. IBM Cloud Pak for Business Automation could allow a local user with access to the container to execute OS system calls.
cvelistv5nvd
CVE-2025-36054MEDIUMCVSS 6.1≥ 24.0.0, ≤ 24.0.0-IF006≥ 24.0.1, ≤ 24.0.1-IF004+1 more2025-11-06
CVE-2025-36054 [MEDIUM] CWE-79 CVE-2025-36054: IBM Business Automation Workflow containers 24.0.0 through 24.0.0-IF006, 24.0.1 through 24.0.1-IF004 IBM Business Automation Workflow containers 24.0.0 through 24.0.0-IF006, 24.0.1 through 24.0.1-IF004, 25.0.0 through 25.0.0-IF001 and IBM Business Automation Workflow traditional with Process Federation Server 24.0.0 through 24.0.1 and 25.0.0 are vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitr
cvelistv5nvd