Impact
The vulnerability in IBM Cloud Pak for Business Automation stems from a broken or risky cryptographic algorithm within the IBM Enterprise Records component. A local attacker who can access the system is able to extract sensitive information, such as stored records or credentials, through the compromised cryptographic process. The weakness is categorized as improper cryptographic algorithm usage (CWE-327) and directly compromises confidentiality of data stored by the application.
Affected Systems
IBM Cloud Pak for Business Automation versions 24.0.0, 24.0.1, 25.0.0, and 26.0.0 are affected. Each version has an interim security fix: 24.0.0-IF009, 24.0.1-IF008, 25.0.0-IF005, and 26.0.0-IF001, along with subsequent security fix releases such as IF002 and IF006. All affected installations should be updated to the latest interim fix available for the specific version. Open‑source libraries used in sub‑components may also contain independent vulnerabilities, but the CVE is specifically addressed by the IBM fixes.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity. Exploitation requires local system access; it is not remotely exploitible and therefore the threat is limited to compromised or privileged users. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits at the time of analysis. Nonetheless, the potential for sensitive data exposure warrants immediate remediation.
OpenCVE Enrichment