IBM Business Automation Workflow containers 24.0.0 through 24.0.0-IF006, 24.0.1 through 24.0.1-IF004, 25.0.0 through 25.0.0-IF001 and IBM Business Automation Workflow traditional with Process Federation Server 24.0.0 through 24.0.1 and 25.0.0 are vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Advisories

No advisories yet.

Fixes

Solution

Remediation/Fixes Affected Product(s) Version(s) Remediation / Fix IBM Business Automation Workflow containers V25.0.0 - V25.0.0-IF001 V24.0.1 - V24.0.1-IF004 V24.0.0 - V24.0.0-IF006 Apply 25.0.0-IF002 or Apply 24.0.1-IF005 or Apply 24.0.0-IF007 IBM Business Automation Workflow traditional with Process Federation Server V25.0.0 V24.0.0 - V24.0.1 earlier unsupported releases Apply DT443492 IBM Business Automation Workflow traditional and containers earlier unsupported releases For earlier and unsupported versions of the products, IBM recommends upgrading to a fixed, supported version of the product.


Workaround

No workaround given by the vendor.

History

Thu, 06 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Nov 2025 14:30:00 +0000

Type Values Removed Values Added
Description IBM Business Automation Workflow containers 24.0.0 through 24.0.0-IF006, 24.0.1 through 24.0.1-IF004, 25.0.0 through 25.0.0-IF001 and IBM Business Automation Workflow traditional with Process Federation Server 24.0.0 through 24.0.1 and 25.0.0 are vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title Cross-site scripting vulnerability affect IBM Business Automation Workflow Process Federation Server -
First Time appeared Ibm
Ibm business Automation Workflow
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:business_automation_workflow:24.0.0:*:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:*:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if006:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.1:*:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.1:*:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.1:if004:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:25.0.0:*:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:25.0.0:*:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:25.0.0:if001:*:*:containers:*:*:*
Vendors & Products Ibm
Ibm business Automation Workflow
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-11-06T14:32:53.254Z

Reserved: 2025-04-15T21:16:11.324Z

Link: CVE-2025-36054

cve-icon Vulnrichment

Updated: 2025-11-06T14:32:47.703Z

cve-icon NVD

Status : Received

Published: 2025-11-06T15:15:46.363

Modified: 2025-11-06T15:15:46.363

Link: CVE-2025-36054

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.