Impact
The vulnerability is a missing authorization check (CWE-862) that permits an authenticated user to perform restricted import actions. Because the system fails to verify that the user has the necessary privileges, an attacker who has a valid session can trigger import jobs that should be protected. This flaw could enable the reading or writing of sensitive business data, effectively granting unauthorized import capabilities across the platform.
Affected Systems
IBM Business Automation Workflow containers and traditional are affected in multiple releases. The vulnerable versions are 24.0.0, 24.0.1, 25.0.0, and 26.0.0. Each release has an interim fix – for example, 26.0.0‑IF002 for both containers and traditional, 25.0.0‑IF006 for the 25.0.0 release, 24.0.1‑IF009 for the 24.0.1 release, and 24.0.0‑IF010 for the 24.0.0 release.
Risk and Exploitability
The CVSS score of 5.4 reflects a medium severity risk due to a missing authorization check. The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating no reported widespread exploitation yet. The attacker must first authenticate to the system, then exploit the missing checks to trigger restricted import actions. Therefore the attack vector is authenticated access.
OpenCVE Enrichment