Known vulnerabilities in Business Automation Insights - page 4

Software CPE: cpe:2.3:a:ibm_corporation:business_automation_insights:*:*:*:*:*:*:*:*
Total vulnerabilities: 247
Public exploits: 17
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Business Automation Insights Business Automation Insights is affected by 247 known vulnerabilities: 1 critical, 43 high, 139 medium, 64 low Critical High Medium Low

Vulnerabilities (247)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU118197 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2020-7751
CWE-1321 Medium
No
No
24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 07.11.2025 SB2020102625
SB2025110755
SB2026010817
#VU118143 - Incorrect Regular Expression
CVE-2016-10540
CWE-185 High
No
No
24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 06.11.2025 SB2018053124
SB2025110755
SB2026010817
and 1 more
#VU115568 - Allocation of Resources Without Limits or Throttling
CVE-2025-36047
CWE-770 Medium
No
No
24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 16.09.2025 SB20250916312
SB20250916316
SB20250916321
and 29 more
#VU115167 - Allocation of Resources Without Limits or Throttling
CVE-2025-58754
CWE-770 Medium
Available
No
24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 12.09.2025 SB2025091204
SB2025100104
SB2025100912
and 51 more
#VU113074 - Stack-based buffer overflow
CVE-2025-36097
CWE-121 High
No
No
24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 18.07.2025 SB20250718100
SB2025072128
SB2025072307
and 43 more
#VU112157 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-48387
CWE-22 High
No
No
24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 03.07.2025 SB2025070352
SB2025070353
SB2025070354
and 13 more
#VU111912 - Heap-based Buffer Overflow
CVE-2025-48060
CWE-122 Medium
No
No
24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 25.06.2025 SB2025032035
SB2025070824
SB2025070826
and 38 more
#VU111223 - Type confusion
CVE-2025-49796
CWE-843 Medium
No
No
24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 17.06.2025 SB2025061728
SB2025070832
SB20250709112
and 84 more
#VU111221 - Use After Free
CVE-2025-49794
CWE-416 Medium
No
No
24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 17.06.2025 SB2025061728
SB2025070832
SB20250709112
and 65 more
#VU111162 - Resource exhaustion
CVE-2025-48976
CWE-400 Medium
Available
No
24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 16.06.2025 SB2025061634
SB2025061635
SB2025061927
and 156 more
#VU110251 - Exposure of sensitive information to an unauthorized actor
CVE-2025-4673
CWE-200 Low
No
No
24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 07.06.2025 SB2025060701
SB2025060702
SB2025061002
and 35 more
#VU105450 - Resource exhaustion
CVE-2025-27144
CWE-400 Medium
No
No
24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 07.03.2025 SB2025030735
SB2025030736
SB2025030737
and 80 more
#VU77566 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2020-36604
CWE-1321 High
No
No
24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 20.06.2023 SB2023062020
SB2023102324
SB2025110755
and 2 more
#VU71577 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-46175
CWE-94 Medium
No
No
24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 26.01.2023 SB2023012644
SB2023012645
SB2023013117
and 44 more
#VU55498 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-15366
CWE-94 Medium
No
No
24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 02.08.2021 SB2020071552
SB2021080213
SB2020120120
and 14 more
#VU54394 - Incorrect Regular Expression
CVE-2020-28500
CWE-185 Medium
No
No
24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 27.06.2021 SB2021062702
SB2021062703
SB2021090905
and 30 more
#VU21764 - Improper Control of Generation of Code ('Code Injection')
CVE-2019-10744
CWE-94 Medium
No
No
24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 14.10.2019 SB2019072612
SB2021012219
SB2022061803
and 14 more
#VU19305 - Improper Control of Generation of Code ('Code Injection')
CVE-2018-16487
CWE-94 High
No
No
24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 22.07.2019 SB2019020111
SB2022062806
SB2022101801
and 13 more
#VU19282 - Resource exhaustion
CVE-2019-1010266
CWE-400 Medium
No
No
24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 22.07.2019 SB2019020111
SB2022062806
SB2022101801
and 8 more
#VU37072 - Improper input validation
CVE-2018-3721
CWE-20 Medium
No
No
24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 07.06.2018 SB2018060730
SB2022062806
SB2022101801
and 7 more


Showing elements 61 - 80 out of 247