Vulnerability Database

300,214

Total vulnerabilities in the database

CVE-2025-36093

IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an attacker to access unauthorized content or perform unauthorized actions using man in the middle techniques due to improper access controls.

  • Published: Nov 3, 2025
  • Updated: Nov 4, 2025
  • CVE: CVE-2025-36093
  • Severity: Low
  • Exploit:

CVSS v3:

  • Severity: Low
  • Score: 4.8
  • AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

CWEs:

Software From Fixed in
ibm / cloud_pak_for_business_automation 24.0.0 24.0.0.x
ibm / cloud_pak_for_business_automation 24.0.0-interim_fix_001 24.0.0-interim_fix_001.x
ibm / cloud_pak_for_business_automation 24.0.0-interim_fix_002 24.0.0-interim_fix_002.x
ibm / cloud_pak_for_business_automation 24.0.0-interim_fix_003 24.0.0-interim_fix_003.x
ibm / cloud_pak_for_business_automation 24.0.0-interim_fix_004 24.0.0-interim_fix_004.x
ibm / cloud_pak_for_business_automation 24.0.1 24.0.1.x
ibm / cloud_pak_for_business_automation 24.0.1-interim_fix_001 24.0.1-interim_fix_001.x
ibm / cloud_pak_for_business_automation 24.0.1-interim_fix_002 24.0.1-interim_fix_002.x
ibm / cloud_pak_for_business_automation 24.0.1-interim_fix_004 24.0.1-interim_fix_004.x
ibm / cloud_pak_for_business_automation 25.0.0 25.0.0.x
ibm / cloud_pak_for_business_automation 25.0.0-interim_fix_001 25.0.0-interim_fix_001.x