Known vulnerabilities in Business Automation Insights - page 5
Vendor:
IBM Corporation
Software:
Business Automation Insights
Software CPE:
cpe:2.3:a:ibm_corporation:business_automation_insights:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
247
Public exploits:
17
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (247)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU118195 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2025-7969 |
CWE-79 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 07.11.2025 |
SB2025110741 SB2025110755 SB2025112543 and 4 more |
||
| #VU118152 - Improper input validation CVE-2025-36092 |
CWE-20 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 06.11.2025 |
SB2025110619 SB2025110755 |
||
| #VU118140 - Unverified Ownership CVE-2025-36091 |
CWE-283 | Low | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 06.11.2025 |
SB2025110609 SB2025110755 |
||
| #VU118139 - Client-Side Enforcement of Server-Side Security CVE-2025-36093 |
CWE-602 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 06.11.2025 |
SB2025110608 SB2025110755 |
||
| #VU114312 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2025-48050 |
CWE-22 | High | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 20.08.2025 |
SB20250820123 SB20250820124 SB20250820125 and 15 more |
||
| #VU113032 - Uncaught Exception CVE-2025-7338 |
CWE-248 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 18.07.2025 |
SB2025071811 SB2025082823 SB2025091818 and 8 more |
||
| #VU78932 - Incorrect Regular Expression CVE-2022-25883 |
CWE-185 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 03.08.2023 |
SB2023080361 SB2023080362 SB2023081514 and 73 more |
||
| #VU76691 - Inefficient Regular Expression Complexity CVE-2022-25901 |
CWE-1333 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 31.05.2023 |
SB2023053112 SB2023053113 SB2023053143 and 10 more |
||
| #VU69942 - Incorrect Regular Expression CVE-2022-3517 |
CWE-185 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 06.12.2022 |
SB2022120638 SB2022120639 SB2022120640 and 48 more |
||
| #VU66439 - Out-of-bounds write CVE-2021-44568 |
CWE-787 | Low | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 12.08.2022 |
SB2021090721 SB2023080920 SB2022031213 and 2 more |
||
| #VU66436 - Out-of-bounds write CVE-2021-33938 |
CWE-787 | Low | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 12.08.2022 |
SB2021090721 SB2022081221 SB2021110327 and 5 more |
||
| #VU66435 - Out-of-bounds write CVE-2021-33930 |
CWE-787 | Low | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 12.08.2022 |
SB2021090721 SB2022081221 SB2021110327 and 5 more |
||
| #VU66064 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2022-1705 |
CWE-444 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 03.08.2022 |
SB2022080321 SB2022080323 SB2022080324 and 86 more |
||
| #VU65355 - Incorrect Regular Expression CVE-2020-7753 |
CWE-185 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 15.07.2022 |
SB2020102724 SB2022071510 SB2023062230 and 12 more |
||
| #VU63553 - Integer overflow CVE-2021-43618 |
CWE-190 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 24.05.2022 |
SB2021121654 SB2022052401 SB2021120223 and 85 more |
||
| #VU61670 - Permissions, Privileges, and Access Controls CVE-2022-0144 |
CWE-264 | Low | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 28.03.2022 |
SB2022032842 SB2022032843 SB2024110620 and 4 more |
||
| #VU59148 - Deserialization of Untrusted Data CVE-2021-46877 |
CWE-502 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 03.01.2022 |
SB2022010326 SB2022010327 SB2022062734 and 37 more |
||
| #VU57967 - Improper input validation CVE-2021-3807 |
CWE-20 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 05.11.2021 |
SB2021110513 SB2021112603 SB2022042257 and 51 more |
||
| #VU41989 - Improper Control of Generation of Code ('Code Injection') CVE-2020-8203 |
CWE-94 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 10.08.2020 |
SB2020071548 SB2020122111 SB2021042308 and 31 more |
||
| #VU26304 - Resource exhaustion CVE-2020-7608 |
CWE-400 | Medium | 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2 | 23.03.2020 |
SB2020032303 SB2023011262 SB2024022730 and 4 more |
Showing elements 81 - 100 out of 247