Unrated severityNVD Advisory· Published Aug 8, 2025· Updated Aug 8, 2025
IBM Cloud Pak for Business Automation security bypass
CVE-2025-36023
Description
IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF005 and 24.0.1 through 24.0.1 IF002 could allow an authenticated user to view sensitive user and system information due to an indirect object reference through a user-controlled key.
Affected products
2- IBM/Cloud Pak for Business Automationv5cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:*:*:*:*:*:*:*Range: 24.0.0
- Range: >= 24.0.0 <= 24.0.0 IF005, >= 24.0.1 <= 24.0.1 IF002
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.ibm.com/support/pages/node/7241570mitrevendor-advisorypatch
News mentions
0No linked articles in our index yet.