Client-Side Enforcement of Server-Side Security in IBM Cloud Pak for Business Automation - CVE-2025-36093

 

Client-Side Enforcement of Server-Side Security in IBM Cloud Pak for Business Automation - CVE-2025-36093

Published: November 6, 2025


Vulnerability identifier: #VU118139
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-36093
CWE-ID: CWE-602
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access unauthorized content or perform unauthorized actions.

The vulnerability exists due to excessive data output by the application. A remote attacker can gain unauthorized content or perform unauthorized actions using man in the middle techniques due to improper access controls.


Affected software

IBM Cloud Pak for Business Automation
Business Automation Insights

How to mitigate CVE-2025-36093

Install updates from vendor's website.

Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2

External References

Related Security Bulletins