Known vulnerabilities in IBM Automation Decision Services 25.0.0.0.1

Version: 25.0.0.0.1
Software CPE: cpe:2.3:a:ibm_corporation:ibm_automation_decision_services:*:*:*:*:*:*:*:*
Total vulnerabilities: 10
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting IBM Automation Decision Services version 25.0.0.0.1 IBM Automation Decision Services 25.0.0.0.1 is affected by 10 vulnerabilities: 9 medium, 1 low Critical High Medium Low

Vulnerabilities (10)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU144038 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-1002
CWE-444 Low
No
No
24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4 18.08.2026 SB2026081830
SB2026081831
SB2026081835
and 2 more
#VU143925 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-33672
CWE-1321 Medium
No
No
24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4 18.08.2026 SB2026081815
SB2026081816
SB2026081831
and 1 more
#VU139384 - Inefficient Regular Expression Complexity
CVE-2026-33671
CWE-1333 Medium
No
No
24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4 26.07.2026 SB2026072609
SB2026072616
SB2026081816
and 2 more
#VU127582 - Allocation of Resources Without Limits or Throttling
CVE-2026-22036
CWE-770 Medium
No
No
24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4 24.04.2026 SB20260424138
SB20260424156
SB20260424157
and 6 more
#VU125981 - Exposure of sensitive information to an unauthorized actor
CVE-2026-40895
CWE-200 Medium
No
No
24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4 14.04.2026 SB20260414106
SB2026062434
SB20260625284
and 13 more
#VU124825 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-29063
CWE-1321 Medium
No
No
24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4 02.04.2026 SB2026040246
SB2026040612
SB2026040627
and 32 more
#VU124423 - Allocation of Resources Without Limits or Throttling
CVE-2026-33871
CWE-770 Medium
No
No
24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4 25.03.2026 SB2026032533
SB20260415180
SB20260422237
and 15 more
#VU124422 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-33870
CWE-444 Medium
Public exploit available
No
24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4 25.03.2026 SB2026032533
SB20260415180
SB2026042043
and 20 more
#VU123491 - Memory corruption
CVE-2026-29062
CWE-119 Medium
No
No
24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4 04.03.2026 SB2026030413
SB2026060232
SB2026060234
and 3 more
#VU119966 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2025-67735
CWE-93 Medium
No
No
24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4 15.12.2025 SB2025121552
SB2025121974
SB2026012079
and 23 more