Impact
IBM Cloud Pak For Business Automation 24.0.0 through 26.0.0 can expose sensitive data when manifest files are read by a remote attacker, allowing them to retrieve confidential information that should not be publicly accessible. This problem arises from improper handling of configuration data and falls under the weakness of exposing sensitive information in externally accessible files (CWE-538). The consequences are that an attacker could learn credentials, internal IP addresses, or other environment secrets without needing additional access privileges, which could lead to further compromise of the business automation environment.
Affected Systems
The affected products are IBM Cloud Pak For Business Automation versions 24.0.0, 24.0.1, 25.0.0, and 26.0.0. These versions are listed in the CNA vendor/product information and are explicitly cited in the advisory links.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the vulnerability is considered exploitable remotely with no clear entry point documented; the EPSS score is not provided, and the vulnerability is not listed in the KEV catalog. The likely attack vector is a remote attacker gaining read access to exposed manifest files, which implies that the vulnerability can be triggered without local user interaction, as long as the manifest files are reachable over the network or through misconfigured file sharing. The risk is moderate but actionable, and remediation is strongly advised.
OpenCVE Enrichment