Execution with unnecessary privileges in IBM Business Automation Workflow - CVE-2025-36059
Published: March 19, 2026
Vulnerability identifier: #VU124133
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-36059
CWE-ID: CWE-250
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to execute OS system calls.
The vulnerability exists due to application binary has a setuid bit. A local low-privileged user with access to the container to execute OS system calls.
Affected software
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
IBM Cloud Pak for Business Automation
How to mitigate CVE-2025-36059
Install updates from vendor's website.
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF007, 24.0.1-IF006, 25.0.0-IF003