Metrics
Affected Vendors & Products
No advisories yet.
Solution
Remediation/Fixes IBM strongly recommends addressing the vulnerability now. Product(s) Version(s) number and/or range Remediation/Fix/Instructions IBM Business Automation Insights 25.0.0 Apply security fix 25.0.0-IF002 IBM Business Automation Insights 24.0.1 Apply security fix 24.0.1-IF005 IBM Business Automation Insights 24.0.0 Apply security fix 24.0.0-IF005
Workaround
Workarounds and Mitigations None.
| Link | Providers | 
|---|---|
| https://www.ibm.com/support/pages/node/7249999 | 
                     | 
            
Mon, 03 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Mon, 03 Nov 2025 16:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an attacker to access unauthorized content or perform unauthorized actions using man in the middle techniques due to improper access controls. | |
| Title | security vulnerabilities are addressed with IBM Business Automation Insights iFixes for October 2025. | |
| First Time appeared | 
        
        Ibm
         Ibm cloud Pak For Business Automation  | 
|
| Weaknesses | CWE-602 | |
| CPEs | cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_for_business_automation:25.0.0:*:*:*:*:*:*:*  | 
|
| Vendors & Products | 
        
        Ibm
         Ibm cloud Pak For Business Automation  | 
|
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-11-03T16:25:26.455Z
Reserved: 2025-04-15T21:16:14.711Z
Link: CVE-2025-36093
Updated: 2025-11-03T16:25:20.905Z
Status : Received
Published: 2025-11-03T16:15:34.763
Modified: 2025-11-03T16:15:34.763
Link: CVE-2025-36093
No data.
                        OpenCVE Enrichment
                    No data.