Known vulnerabilities in Business Automation Insights - page 4
Vendor:
IBM Corporation
Software:
Business Automation Insights
Software CPE:
cpe:2.3:a:ibm_corporation:business_automation_insights:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
247
Public exploits:
17
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (247)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU118197 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\') CVE-2020-7751 |
CWE-1321 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 07.11.2025 |
SB2020102625 SB2025110755 SB2026010817 |
||
| #VU118143 - Incorrect Regular Expression CVE-2016-10540 |
CWE-185 | High | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 06.11.2025 |
SB2018053124 SB2025110755 SB2026010817 and 1 more |
||
| #VU115568 - Allocation of Resources Without Limits or Throttling CVE-2025-36047 |
CWE-770 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 16.09.2025 |
SB20250916312 SB20250916316 SB20250916321 and 29 more |
||
| #VU115167 - Allocation of Resources Without Limits or Throttling CVE-2025-58754 |
CWE-770 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 12.09.2025 |
SB2025091204 SB2025100104 SB2025100912 and 51 more |
||
| #VU113074 - Stack-based buffer overflow CVE-2025-36097 |
CWE-121 | High | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 18.07.2025 |
SB20250718100 SB2025072128 SB2025072307 and 43 more |
||
| #VU112157 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2025-48387 |
CWE-22 | High | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 03.07.2025 |
SB2025070352 SB2025070353 SB2025070354 and 13 more |
||
| #VU111912 - Heap-based Buffer Overflow CVE-2025-48060 |
CWE-122 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 25.06.2025 |
SB2025032035 SB2025070824 SB2025070826 and 38 more |
||
| #VU111223 - Type confusion CVE-2025-49796 |
CWE-843 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 17.06.2025 |
SB2025061728 SB2025070832 SB20250709112 and 84 more |
||
| #VU111221 - Use After Free CVE-2025-49794 |
CWE-416 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 17.06.2025 |
SB2025061728 SB2025070832 SB20250709112 and 65 more |
||
| #VU111162 - Resource exhaustion CVE-2025-48976 |
CWE-400 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 16.06.2025 |
SB2025061634 SB2025061635 SB2025061927 and 156 more |
||
| #VU110251 - Exposure of sensitive information to an unauthorized actor CVE-2025-4673 |
CWE-200 | Low | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 07.06.2025 |
SB2025060701 SB2025060702 SB2025061002 and 35 more |
||
| #VU105450 - Resource exhaustion CVE-2025-27144 |
CWE-400 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 07.03.2025 |
SB2025030735 SB2025030736 SB2025030737 and 80 more |
||
| #VU77566 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\') CVE-2020-36604 |
CWE-1321 | High | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 20.06.2023 |
SB2023062020 SB2023102324 SB2025110755 and 2 more |
||
| #VU71577 - Improper Control of Generation of Code ('Code Injection') CVE-2022-46175 |
CWE-94 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 26.01.2023 |
SB2023012644 SB2023012645 SB2023013117 and 44 more |
||
| #VU55498 - Improper Control of Generation of Code ('Code Injection') CVE-2020-15366 |
CWE-94 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 02.08.2021 |
SB2020071552 SB2021080213 SB2020120120 and 14 more |
||
| #VU54394 - Incorrect Regular Expression CVE-2020-28500 |
CWE-185 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 27.06.2021 |
SB2021062702 SB2021062703 SB2021090905 and 30 more |
||
| #VU21764 - Improper Control of Generation of Code ('Code Injection') CVE-2019-10744 |
CWE-94 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 14.10.2019 |
SB2019072612 SB2021012219 SB2022061803 and 14 more |
||
| #VU19305 - Improper Control of Generation of Code ('Code Injection') CVE-2018-16487 |
CWE-94 | High | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 22.07.2019 |
SB2019020111 SB2022062806 SB2022101801 and 13 more |
||
| #VU19282 - Resource exhaustion CVE-2019-1010266 |
CWE-400 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 22.07.2019 |
SB2019020111 SB2022062806 SB2022101801 and 8 more |
||
| #VU37072 - Improper input validation CVE-2018-3721 |
CWE-20 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 07.06.2018 |
SB2018060730 SB2022062806 SB2022101801 and 7 more |
Showing elements 61 - 80 out of 247