Input validation error in IBM Cloud Pak for Business Automation - CVE-2025-36094
Published: February 24, 2026
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote user can pass specially crafted input to the application and perform a denial of service (DoS) attack corrupt existing data due to the improper validation of input length.
Affected software
Business Automation Insights
How to mitigate CVE-2025-36094
Business Automation Insights - addressed in versions 24.0.0.0.6, 24.0.1.0.6, 25.0.0.0.3