IBM Business Automation Workflow containers V25.0.0 through V25.0.0-IF007, V24.0.1 - V24.0.1-IF007, V24.0.0 - V24.0.0-IF007 and IBM Business Automation Workflow traditional V25.0.0, V24.0.1, V24.0.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Advisories

No advisories yet.

Fixes

Solution

The recommended solution is to apply the Interim Fix (iFix) or Cumulative Fix (CF) containing DT456229 https://www.ibm.com/mysupport/aCIgJ0000007aZpWAI  as soon as practical. Affected Product(s)Version(s)Remediation / FixIBM Business Automation Workflow containersV25.0.0Apply 25.0.0-IF003 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-containers-25000-interim-fixes IBM Business Automation Workflow containersV24.0.1Apply 24.0.1-IF006 https://www.ibm.com/support/pages/node/7183042 IBM Business Automation Workflow containersV24.0.0Apply 24.0.0-IF008 https://www.ibm.com/support/pages/node/7159792 IBM Business Automation Workflow traditionalV25.0.0Apply DT456229 https://www.ibm.com/mysupport/aCIgJ0000007aZpWAI  included in 25.0.0-IF003 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-25000-interim-fixes IBM Business Automation Workflow traditional V24.0.1Apply DT456229 https://www.ibm.com/mysupport/aCIgJ0000007aZpWAI  included in 24.0.1-IF006 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-24010-interim-fixes IBM Business Automation Workflow traditional  V24.0.0Apply DT456229 https://www.ibm.com/mysupport/aCIgJ0000007aZpWAI  included in 24.0.0-IF008 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-24000-interim-fixes


Workaround

No workaround given by the vendor.

History

Mon, 02 Feb 2026 23:15:00 +0000

Type Values Removed Values Added
Description IBM Business Automation Workflow containers V25.0.0 through V25.0.0-IF007, V24.0.1 - V24.0.1-IF007, V24.0.0 - V24.0.0-IF007 and IBM Business Automation Workflow traditional V25.0.0, V24.0.1, V24.0.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Title XML eXternal Entity injection (XXE) vulnerability affect IBM Business Automation Workflow -
First Time appeared Ibm
Ibm business Automation Workflow
Weaknesses CWE-918
CPEs cpe:2.3:a:ibm:business_automation_workflow:24.0.0:*:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:*:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if008:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.1:*:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.1:*:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.1:if006:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:25.0.0:*:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:25.0.0:*:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:25.0.0:if003:*:*:containers:*:*:*
Vendors & Products Ibm
Ibm business Automation Workflow
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-02-02T20:56:48.318Z

Reserved: 2025-11-12T21:55:13.229Z

Link: CVE-2025-13096

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-02T23:15:58.600

Modified: 2026-02-02T23:15:58.600

Link: CVE-2025-13096

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses