6.5
CVE-2026-11864
- EPSS 0.37%
- Veröffentlicht 15.09.2026 17:30:12
- Zuletzt bearbeitet 16.09.2026 19:24:58
- Erkennungen
Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026.
IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive application data and/or determine the structure of the XML document.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerIBM
≫
Produkt
Cloud Pak for Business Automation
Version <=
26.0.0 Interim Fix 001
Version
26.0.0
Status
affected
Version <=
25.0.0 Interim Fix 005
Version
25.0.0
Status
affected
Version <=
24.0.1 Interim Fix 008
Version
24.0.1
Status
affected
Version <=
24.0.0 Interim Fix 009
Version
24.0.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.37% | 0.308 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| IBM | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-643 Improper Neutralization of Data within XPath Expressions ('XPath Injection')
The product uses external input to dynamically construct an XPath expression used to retrieve data from an XML database, but it does not neutralize or incorrectly neutralizes that input. This allows an attacker to control the structure of the query.
https://www.ibm.com/support/pages/node/7285931