Known vulnerabilities in Business Automation Insights - page 2
Vendor:
IBM Corporation
Software:
Business Automation Insights
Software CPE:
cpe:2.3:a:ibm_corporation:business_automation_insights:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
247
Public exploits:
17
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (247)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU123158 - Improper input validation CVE-2025-36094 |
CWE-20 | Low | 24.0.0.0.6, 24.0.1.0.6, 25.0.0.0.3 | 24.02.2026 |
SB2026022410 SB2026022411 |
||
| #VU122837 - Incorrect Permission Assignment for Critical Resource CVE-2025-12985 |
CWE-732 | Low | 24.0.0.0.5, 24.0.1.0.6, 25.0.0.0.3 | 16.02.2026 |
SB2026021608 SB2026021609 |
||
| #VU116684 - Improper input validation CVE-2025-11226 |
CWE-20 | Medium | 24.0.0.0.6, 24.0.1.0.6, 25.0.0.0.3 | 07.10.2025 |
SB2025100745 SB2025100746 SB2025112108 and 19 more |
||
| #VU115571 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2025-36000 |
CWE-79 | Low | 24.0.0.0.5, 24.0.1.0.6, 25.0.0.0.3 | 16.09.2025 |
SB20250916311 SB20250916316 SB2025092515 and 25 more |
||
| #VU114088 - Stack-based buffer overflow CVE-2025-5222 |
CWE-121 | High | 24.0.0.0.5, 24.0.1.0.6, 25.0.0.0.3 | 14.08.2025 |
SB2025081454 SB2025081455 SB2025081456 and 34 more |
||
| #VU114006 - Privilege Chaining CVE-2025-36124 |
CWE-268 | High | 24.0.0.0.5, 24.0.1.0.6, 25.0.0.0.3 | 13.08.2025 |
SB2025081354 SB2025082918 SB2025082921 and 23 more |
||
| #VU113648 - NULL Pointer Dereference CVE-2024-13978 |
CWE-476 | Low | 24.0.0.0.6, 24.0.1.0.6, 25.0.0.0.3 | 05.08.2025 |
SB2025080553 SB2025080846 SB2025081318 and 8 more |
||
| #VU113607 - Uncontrolled Recursion CVE-2025-48924 |
CWE-674 | Medium | 24.0.0.0.5, 24.0.1.0.6, 25.0.0.0.3 | 04.08.2025 |
SB2025080422 SB2025080423 SB2025080427 and 180 more |
||
| #VU113526 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2025-40909 |
CWE-362 | Low | 24.0.0.0.5, 24.0.1.0.6, 25.0.0.0.3 | 31.07.2025 |
SB2025073123 SB2025073125 SB2025073126 and 43 more |
||
| #VU112255 - Deserialization of Untrusted Data CVE-2025-27818 |
CWE-502 | Medium | 24.0.0.0.5, 24.0.1.0.6, 25.0.0.0.3 | 04.07.2025 |
SB20250704102 SB2025070708 SB2025080519 and 16 more |
||
| #VU112146 - Server-Side Request Forgery (SSRF) CVE-2025-27817 |
CWE-918 | High | 24.0.0.0.5, 24.0.1.0.6, 25.0.0.0.3 | 03.07.2025 |
SB2025070339 SB2025070340 SB2025070345 and 42 more |
||
| #VU109840 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2025-47273 |
CWE-22 | High | 24.0.0.0.5, 24.0.1.0.6, 25.0.0.0.3 | 27.05.2025 |
SB2025052721 SB2025052734 SB2025052736 and 112 more |
||
| #VU106253 - Improper input validation CVE-2025-22870 |
CWE-20 | Medium | 24.0.0.0.6, 24.0.1.0.6, 25.0.0.0.3 | 30.03.2025 |
SB2025033001 SB2025033002 SB2025033003 and 106 more |
||
| #VU105112 - Resource exhaustion CVE-2025-23184 |
CWE-400 | Medium | 24.0.0.0.5, 24.0.1.0.6, 25.0.0.0.3 | 28.02.2025 |
SB2025022807 SB2025030340 SB2025041017 and 40 more |
||
| #VU90156 - Security Features CVE-2024-35195 |
CWE-254 | Low | 24.0.0.0.5, 24.0.1.0.6, 25.0.0.0.3 | 31.05.2024 |
SB2024053174 SB2024053188 SB2024053192 and 117 more |
||
| #VU89351 - Insufficient Verification of Data Authenticity CVE-2024-34397 |
CWE-345 | Low | 24.0.0.0.5, 24.0.1.0.6, 25.0.0.0.3 | 10.05.2024 |
SB2024051042 SB2024051043 SB2024051044 and 88 more |
||
| #VU85368 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2024-22195 |
CWE-79 | Medium | 24.0.0.0.6, 24.0.1.0.6, 25.0.0.0.3 | 15.01.2024 |
SB2024011508 SB2024011512 SB2024011513 and 60 more |
||
| #VU77526 - Permissions, Privileges, and Access Controls CVE-2023-2728 |
CWE-264 | Medium | 24.0.0.0.5, 24.0.1.0.6, 25.0.0.0.3 | 19.06.2023 |
SB2023061947 SB2023061950 SB2023061951 and 15 more |
||
| #VU77525 - Permissions, Privileges, and Access Controls CVE-2023-2727 |
CWE-264 | Medium | 24.0.0.0.5, 24.0.1.0.6, 25.0.0.0.3 | 19.06.2023 |
SB2023061947 SB2023061950 SB2023061951 and 15 more |
||
| #VU22494 - Heap-based Buffer Overflow CVE-2019-17543 |
CWE-122 | High | 24.0.0.0.5, 24.0.1.0.6, 25.0.0.0.3 | 04.11.2019 |
SB2019110405 SB2019102917 SB2019102918 and 12 more |
Showing elements 21 - 40 out of 247