IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF005 and 24.0.1 through 24.0.1 IF002 could allow an authenticated user to view sensitive user and system information due to an indirect object reference through a user-controlled key.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.ibm.com/support/pages/node/7241570 |
![]() ![]() |
History
Fri, 08 Aug 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 08 Aug 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF005 and 24.0.1 through 24.0.1 IF002 could allow an authenticated user to view sensitive user and system information due to an indirect object reference through a user-controlled key. | |
Title | IBM Cloud Pak for Business Automation security bypass | |
First Time appeared |
Ibm
Ibm cloud Pak For Business Automation |
|
Weaknesses | CWE-639 | |
CPEs | cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:ifix5:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:ifix2:*:*:*:*:*:* |
|
Vendors & Products |
Ibm
Ibm cloud Pak For Business Automation |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ibm
Published: 2025-08-08T14:51:12.631Z
Updated: 2025-08-08T15:07:16.477Z
Reserved: 2025-04-15T21:16:08.835Z
Link: CVE-2025-36023

Updated: 2025-08-08T15:07:09.436Z

Status : Awaiting Analysis
Published: 2025-08-08T15:15:28.087
Modified: 2025-08-08T20:30:18.180
Link: CVE-2025-36023

No data.