Input validation error in IBM Cloud Pak for Business Automation - CVE-2025-36094

 

Input validation error in IBM Cloud Pak for Business Automation - CVE-2025-36094

Published: February 24, 2026


Vulnerability identifier: #VU123158
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-36094
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote user can pass specially crafted input to the application and perform a denial of service (DoS) attack corrupt existing data due to the improper validation of input length.


Affected software

IBM Cloud Pak for Business Automation
Business Automation Insights

How to mitigate CVE-2025-36094

Install updates from vendor's website.

IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF006, 24.0.1-IF006, 25.0.0-IF003
Business Automation Insights - addressed in versions 24.0.0.0.6, 24.0.1.0.6, 25.0.0.0.3

External References

Related Security Bulletins