Impact
IBM Business Automation Workflow containers and traditional are vulnerable to XML external entity injection. This weakness can allow a remote attacker to read sensitive configuration data or other protected files and cause excessive memory consumption that could lead to a denial of service. The flaw is classified as CWE-611 and has a CVSS score of 7.1, indicating a high severity. The description explicitly states that a remote attacker could expose sensitive information or consume memory resources.
Affected Systems
The affected systems are IBM Business Automation Workflow containers and traditional deployments. Versions from 24.0.0 through 26.0.0 are impacted, with specific interim fixes such as 24.0.0-IF009, 24.0.1-IF008, 25.0.0-IF005, and 26.0.0-IF001/IF002 available.
Risk and Exploitability
The CVSS score of 7.1 places this vulnerability in the high severity category. The EPSS score is 0.00496, indicating a very low but nonzero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting limited publicly known exploitation at this time. The likely attack vector is remote via XML data processing, as the description indicates an external entity injection. Therefore, any system that accepts untrusted XML input is at risk, though the absence of a public exploit reduces the immediate threat.
OpenCVE Enrichment