Impact
The flaw is an XPath injection that enables an authenticated user to manipulate XML queries and gain unauthorized read access to application data. This can allow extraction of confidential information or full disclosure of XML document structure, a data‑disclosure and configuration‑exposure weakness classified as CWE‑643.
Affected Systems
Affected versions are IBM Cloud Pak for Business Automation releases 24.0.0 through interim fix 009, 24.0.1 through interim fix 008, 25.0.0 through interim fix 005, and 26.0.0 through interim fix 001. Each release series contains the specified interim fix that includes the vulnerability.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium impact. The EPSS is not available and the vulnerability is not listed in CISA KEV. Attackers require authenticated access; therefore the threat is constrained to accounts with permission to query the system’s XML data. In environments with strict role‑based access controls the attack surface may be limited, but any successful exploitation would result in confidential data exposure.
OpenCVE Enrichment