Impact
The vulnerability is an XPath injection flaw in IBM Cloud Pak for Business Automation that permits an authenticated attacker to construct malicious XPath queries against the application's XML data store. By injecting specially crafted expressions, a legitimate user can read or infer the contents of sensitive documents or reveal the structure of the XML schema. The flaw is present in the 26.0.0 release with Interim Fix 001, 25.0.0 with Interim Fix 005, 24.0.1 with Interim Fix 008, and 24.0.0 with Interim Fix 009, and may affect any open‑source sub‑components bundled within the product if they are not updated to the patched versions.
Affected Systems
IBM Cloud Pak for Business Automation versions 26.0.0 (Interim Fix 001), 25.0.0 (Interim Fix 005), 24.0.1 (Interim Fix 008), and 24.0.0 (Interim Fix 009). Any open‑source libraries inside the product may also be vulnerable if they are not synchronized with the interim fixes.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity risk, while the EPSS score of <1% shows a very low but non‑zero probability of exploitation. The flaw is not listed in the CISA KEV catalog, suggesting it is not widely exploited in the wild. Attackers must be authenticated and must have sufficient permissions to execute XPath queries; with strict role‑based access control the attack surface is limited, but privileged accounts can still exploit the issue.
OpenCVE Enrichment