5.3

CVE-2026-12762

Insertion of Sensitive Information into Externally-Accessible File in IBM Business Automation Insights

IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in manifest files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Business Automation Insights Version 24.0.0 Update -
Ibm ≫ Business Automation Insights Version 24.0.0 Update interim_fix001
Ibm ≫ Business Automation Insights Version 24.0.0 Update interim_fix002
Ibm ≫ Business Automation Insights Version 24.0.0 Update interim_fix003
Ibm ≫ Business Automation Insights Version 24.0.0 Update interim_fix004
Ibm ≫ Business Automation Insights Version 24.0.0 Update interim_fix005
Ibm ≫ Business Automation Insights Version 24.0.0 Update interim_fix006
Ibm ≫ Business Automation Insights Version 24.0.0 Update interim_fix007
Ibm ≫ Business Automation Insights Version 24.0.1 Update -
Ibm ≫ Business Automation Insights Version 24.0.1 Update interim_fix001
Ibm ≫ Business Automation Insights Version 24.0.1 Update interim_fix002
Ibm ≫ Business Automation Insights Version 24.0.1 Update interim_fix003
Ibm ≫ Business Automation Insights Version 24.0.1 Update interim_fix004
Ibm ≫ Business Automation Insights Version 24.0.1 Update interim_fix005
Ibm ≫ Business Automation Insights Version 24.0.1 Update interim_fix006
Ibm ≫ Business Automation Insights Version 24.0.1 Update interim_fix007
Ibm ≫ Business Automation Insights Version 25.0.0 Update -
Ibm ≫ Business Automation Insights Version 25.0.0 Update interim_fix001
Ibm ≫ Business Automation Insights Version 25.0.0 Update interim_fix002
Ibm ≫ Business Automation Insights Version 25.0.0 Update interim_fix003
Ibm ≫ Business Automation Insights Version 25.0.0 Update interim_fix004
Ibm ≫ Business Automation Insights Version 25.0.0 Update interim_fix005
Ibm ≫ Business Automation Insights Version 26.0.0 Update -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.152
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
IBM 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-538 Insertion of Sensitive Information into Externally-Accessible File or Directory

The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.

https://www.ibm.com/support/pages/node/7282605
Vendor Advisory