Description
IBM Business Automation Workflow containers and traditional may use programming model artifacts that are vulnerable to XML Entity Injection attacks by default.
Published: 2026-09-14
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists because IBM use programming model artifacts that are configured by default to allow XML entity injection. An attacker can craft XML input containing external entities that the application will resolve, potentially exposing sensitive data or, in some configurations, executing arbitrary code. This flaw is identified as CWE-611, reflecting insufficient restriction of XML external entities.

Affected Systems

IBM Business Automation Workflow containers and the traditional edition from release 24.0.0 through 26.0.0 contain components vulnerable to XML entity injection. Interim fixes are provided for each release: 24.0.0 uses Interim Fix 010, 24.0.1 uses Interim Fix 009, 25.0.0 uses Interim Fix 006, and 26.0.0 uses Interim Fix 001 and the subsequent full interim patch 002. Users should follow IBM’s documentation for installing the appropriate fix for their deployment.

Risk and Exploitability

With a CVSS score of 7.1 the vulnerability is considered moderate‑to‑high severity, and an EPSS score of less than 1% indicates that, as of now, exploitation is unlikely but non‑zero. The vulnerability is not listed in CISA’s KEV catalog, meaning there are no publicly documented exploits. The likely attack vector involves an attacker submitting crafted XML data to a component that parses XML, which may require internal or authenticated access reflects the risk of potential data exposure or code execution.

Generated by OpenCVE AI on September 20, 2026 at 21:58 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Affected Product(s)Version(s)Remediation / FixIBM Business Automation Workflow containersV26.0.0 - V26.0.0-IF001Apply container 26.0.0-IF002 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-containers-26000-interim-fixes IBM Business Automation Workflow traditionalV26.0.0 - V26.0.0-IF001Apply traditional 26.0.0-IF002 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-26000-interim-fixes IBM Business Automation Workflow containersV25.0.0 - V25.0.0-IF005Apply container 25.0.0-IF006 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-containers-25000-interim-fixes IBM Business Automation Workflow traditionalV25.0.0 - V25.0.0-IF005Apply traditional 25.0.0-IF006 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-25000-interim-fixes IBM Business Automation Workflow containersV24.0.1 - V24.0.1-IF008Apply container 24.0.1-IF009 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-containers-24010-interim-fixes IBM Business Automation Workflow traditionalV24.0.1 - V24.0.1-IF008Apply traditional 24.0.1-IF009 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-24010-interim-fixes IBM Business Automation Workflow containersV24.0.0 - V24.0.0-IF009Apply container 24.0.0-IF010 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-containers-24000-interim-fixes IBM Business Automation Workflow traditionalV24.0.0 - V24.0.0-IF009Apply traditional 24.0.0-IF010 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-24000-interim-fixes


OpenCVE Recommended Actions

  • Update to the latest interim packages for your current version (26.0.0‑IF002 for containers and traditional, or apply the applicable version‑specific interim fix for 24.x or 25.x the most recent product version.
  • Modify the XML parsing configuration to disable external entity resolution or use a secure XML parser that rejects external entities.
  • Continuously monitor application logs for unusual XML processing activity and verify that the update has been deployed in the intended environment.

Generated by OpenCVE AI on September 20, 2026 at 21:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM Business Automation Workflow containers and traditional may use programming model artifacts that are vulnerable to XML Entity Injection attacks by default.
Title Multiple secuirty vulnerabilies addressed with IBM Business Automation Workflow August 2026
First Time appeared Ibm
Ibm business Automation Workflow Containers And Traditional
Weaknesses CWE-611
CPEs cpe:2.3:a:ibm:business_automation_workflow_containers_and_traditional:24.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:business_automation_workflow_containers_and_traditional:24.0.0:interim_fix_009:*:*:*:*:*:*
cpe:2.3:a:ibm:business_automation_workflow_containers_and_traditional:24.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:business_automation_workflow_containers_and_traditional:24.0.1:interim_fix_008:*:*:*:*:*:*
cpe:2.3:a:ibm:business_automation_workflow_containers_and_traditional:25.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:business_automation_workflow_containers_and_traditional:25.0.0:interim_fix_005:*:*:*:*:*:*
cpe:2.3:a:ibm:business_automation_workflow_containers_and_traditional:26.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:business_automation_workflow_containers_and_traditional:26.0.0:interim_fix_001:*:*:*:*:*:*
Vendors & Products Ibm
Ibm business Automation Workflow Containers And Traditional
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}


Subscriptions

Ibm Business Automation Workflow Containers And Traditional
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T17:31:48.482Z

Reserved: 2026-06-23T19:49:40.099Z

Link: CVE-2026-13107

cve-icon Vulnrichment

Updated: 2026-09-15T17:27:08.198Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T21:17:00.980

Modified: 2026-09-16T19:24:58.293

Link: CVE-2026-13107

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:00:09Z

Weaknesses
  • CWE-611

    Improper Restriction of XML External Entity Reference