Impact
The vulnerability exists because IBM use programming model artifacts that are configured by default to allow XML entity injection. An attacker can craft XML input containing external entities that the application will resolve, potentially exposing sensitive data or, in some configurations, executing arbitrary code. This flaw is identified as CWE-611, reflecting insufficient restriction of XML external entities.
Affected Systems
IBM Business Automation Workflow containers and the traditional edition from release 24.0.0 through 26.0.0 contain components vulnerable to XML entity injection. Interim fixes are provided for each release: 24.0.0 uses Interim Fix 010, 24.0.1 uses Interim Fix 009, 25.0.0 uses Interim Fix 006, and 26.0.0 uses Interim Fix 001 and the subsequent full interim patch 002. Users should follow IBM’s documentation for installing the appropriate fix for their deployment.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is considered moderate‑to‑high severity, and an EPSS score of less than 1% indicates that, as of now, exploitation is unlikely but non‑zero. The vulnerability is not listed in CISA’s KEV catalog, meaning there are no publicly documented exploits. The likely attack vector involves an attacker submitting crafted XML data to a component that parses XML, which may require internal or authenticated access reflects the risk of potential data exposure or code execution.
OpenCVE Enrichment