5.4
CVE-2026-12751
- EPSS 0.27%
- Veröffentlicht 15.09.2026 17:03:34
- Zuletzt bearbeitet 23.09.2026 20:15:43
- Erkennungen
Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026.
IBM Cloud Pak for Business Automation is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Cloud Pak For Business Automation Version 24.0.0 Update -
Ibm ≫ Cloud Pak For Business Automation Version 24.0.0 Update interim_fix_001
Ibm ≫ Cloud Pak For Business Automation Version 24.0.0 Update interim_fix_002
Ibm ≫ Cloud Pak For Business Automation Version 24.0.0 Update interim_fix_003
Ibm ≫ Cloud Pak For Business Automation Version 24.0.0 Update interim_fix_004
Ibm ≫ Cloud Pak For Business Automation Version 24.0.0 Update interim_fix_005
Ibm ≫ Cloud Pak For Business Automation Version 24.0.0 Update interim_fix_006
Ibm ≫ Cloud Pak For Business Automation Version 24.0.0 Update interim_fix_007
Ibm ≫ Cloud Pak For Business Automation Version 24.0.0 Update interim_fix_008
Ibm ≫ Cloud Pak For Business Automation Version 24.0.0 Update interim_fix_009
Ibm ≫ Cloud Pak For Business Automation Version 26.0.0 Update -
Ibm ≫ Cloud Pak For Business Automation Version 26.0.0 Update interim_fix_001
Ibm ≫ Cloud Pak For Business Automation Version 24.0.1 Update -
Ibm ≫ Cloud Pak For Business Automation Version 24.0.1 Update interim_fix_001
Ibm ≫ Cloud Pak For Business Automation Version 24.0.1 Update interim_fix_002
Ibm ≫ Cloud Pak For Business Automation Version 24.0.1 Update interim_fix_003
Ibm ≫ Cloud Pak For Business Automation Version 24.0.1 Update interim_fix_004
Ibm ≫ Cloud Pak For Business Automation Version 24.0.1 Update interim_fix_005
Ibm ≫ Cloud Pak For Business Automation Version 24.0.1 Update interim_fix_006
Ibm ≫ Cloud Pak For Business Automation Version 24.0.1 Update interim_fix_007
Ibm ≫ Cloud Pak For Business Automation Version 24.0.1 Update interim_fix_008
Ibm ≫ Cloud Pak For Business Automation Version 25.0.0 Update -
Ibm ≫ Cloud Pak For Business Automation Version 25.0.0 Update interim_fix_001
Ibm ≫ Cloud Pak For Business Automation Version 25.0.0 Update interim_fix_002
Ibm ≫ Cloud Pak For Business Automation Version 25.0.0 Update interim_fix_003
Ibm ≫ Cloud Pak For Business Automation Version 25.0.0 Update interim_fix_004
Ibm ≫ Cloud Pak For Business Automation Version 25.0.0 Update interim_fix_005
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.192 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| IBM | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.
https://www.ibm.com/support/pages/node/7285931