6.1

CVE-2025-36054

Cross-site scripting vulnerability affect IBM Business Automation Workflow Process Federation Server -

IBM Business Automation Workflow containers 24.0.0 through 24.0.0-IF006, 24.0.1 through 24.0.1-IF004, 25.0.0 through 25.0.0-IF001 and IBM Business Automation Workflow traditional with Process Federation Server 24.0.0 through 24.0.1 and 25.0.0 are vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Business Automation Workflow Version - SwEdition traditional
Ibm ≫ Business Automation Workflow Version 24.0.0 Update - SwEdition containers
Ibm ≫ Business Automation Workflow Version 24.0.0 Update if001 SwEdition containers
Ibm ≫ Business Automation Workflow Version 24.0.0 Update if002 SwEdition containers
Ibm ≫ Business Automation Workflow Version 24.0.0 Update if003 SwEdition containers
Ibm ≫ Business Automation Workflow Version 24.0.0 Update if004 SwEdition containers
Ibm ≫ Business Automation Workflow Version 24.0.0 Update if005 SwEdition containers
Ibm ≫ Business Automation Workflow Version 24.0.0 Update if006 SwEdition containers
Ibm ≫ Business Automation Workflow Version 24.0.1 Update - SwEdition containers
Ibm ≫ Business Automation Workflow Version 24.0.1 Update if001 SwEdition containers
Ibm ≫ Business Automation Workflow Version 24.0.1 Update if002 SwEdition containers
Ibm ≫ Business Automation Workflow Version 24.0.1 Update if004 SwEdition containers
Ibm ≫ Business Automation Workflow Version 25.0.0 Update - SwEdition containers
Ibm ≫ Business Automation Workflow Version 25.0.0 Update if001 SwEdition containers
Ibm ≫ Process Federation Server Version 24.0.0
Ibm ≫ Process Federation Server Version 24.0.1
Ibm ≫ Process Federation Server Version 25.0.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.098
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
IBM 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://www.ibm.com/support/pages/node/7250261
Patch
Vendor Advisory