Impact
IBM Cloud Pak for Business Automation contains a flaw that allows an authenticated user to trigger a denial of service by consuming an excessive amount of system resources. The vulnerability is characterized by misuse of resource allocation, leading to service degradation or interruption. The description does not explicitly state any privilege escalation or data exfiltration capabilities, so the impact is limited to availability.
Affected Systems
The affected product is IBM Cloud Pak for Business Automation. The vulnerability affects multiple releases: version 26.0.0 (interim fix IF001), 25.0.0 (interim fix IF006), 24.0.1 (interim fix IF009), and 24.0.0 (interim fix IF010). The issue may involve open source libraries that are part of the deployment, so any component containing those libraries could be impacted, depending on how the product is configured.
Risk and Exploitability
The CVSS score of 6.5 places this vulnerability in the medium severity range. Although the EPSS score of < 1% indicates a very low likelihood of exploitation and the vulnerability is not listed in the CISA KEV catalog, the requirement for authentication suggests that the attack surface is limited to users who already have valid access to the system. The lack of evidence for widespread exploitation does not eliminate the risk, because an insider or compromised account could exploit the flaw to disrupt service. Enterprises should prioritize mitigation due to the potential for significant availability impact.
OpenCVE Enrichment