Impact
The vulnerability is an improper validation of HTTP headers that lets a remote attacker bypass the existing authorization controls in IBM Cloud Pak for Business Automation. By manipulating these headers, an attacker can invoke restricted API endpoints that normally require elevated privileges, potentially exposing sensitive data, altering business processes, or executing unauthorized commands. The weakness is classified as an authorization bypass, which can cause loss of confidentiality and integrity of business operations.
Affected Systems
IBM Cloud Pak for Business Automation versions 24.0.0, 24.0.1, 25.0.0, and 26.0.0 are impacted. 24.0.0 requires interim fix 009 or 010, 24.0.1 requires interim fix 008 or 009, 25.0.0 requires interim fix 005 or 006, and 26.0.0 requires interim fix 001 or 002. The fix updates address the header validation flaw and restore proper authorization checks.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. Exploitation is possible over the network through normal HTTP traffic, and no special conditions are currently known. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Attackers can trivially trigger the flaw by sending crafted HTTP requests to privileged endpoints, so patching is recommended.
OpenCVE Enrichment