PT-2025-32362 · Ibm · Ibm Cloud Pak For Business Automation

Published

2025-08-08

·

Updated

2025-08-15

·

CVE-2025-36023

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Cloud Pak for Business Automation versions 24.0.0 through 24.0.0 IF005 IBM Cloud Pak for Business Automation versions 24.0.1 through 24.0.1 IF002
Description The software contains a flaw that may allow an authenticated user to view sensitive user and system information due to an indirect object reference through a user-controlled key.
Recommendations IBM Cloud Pak for Business Automation versions 24.0.0 through 24.0.0 IF005: At the moment, there is no information about a newer version that contains a fix for this vulnerability. IBM Cloud Pak for Business Automation versions 24.0.1 through 24.0.1 IF002: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-36023

Affected Products

Ibm Cloud Pak For Business Automation