Client-Side Enforcement of Server-Side Security in IBM Cloud Pak for Business Automation - CVE-2025-36093
Published: November 6, 2025
Vulnerability identifier: #VU118139
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-36093
CWE-ID: CWE-602
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access unauthorized content or perform unauthorized actions.
The vulnerability exists due to excessive data output by the application. A remote attacker can gain unauthorized content or perform unauthorized actions using man in the middle techniques due to improper access controls.
Affected software
IBM Cloud Pak for Business Automation
Business Automation Insights
Business Automation Insights
How to mitigate CVE-2025-36093
Install updates from vendor's website.
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2