VYPR
Unrated severityNVD Advisory· Published Aug 8, 2025· Updated Aug 8, 2025

IBM Cloud Pak for Business Automation security bypass

CVE-2025-36023

Description

IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF005 and 24.0.1 through 24.0.1 IF002 could allow an authenticated user to view sensitive user and system information due to an indirect object reference through a user-controlled key.

Affected products

2
  • IBM/Cloud Pak for Business Automationv5
    cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:*:*:*:*:*:*:*
    Range: 24.0.0
  • Range: >= 24.0.0 <= 24.0.0 IF005, >= 24.0.1 <= 24.0.1 IF002

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.