CVE-2025-36059: Multiple security vulnerabilities are addressed in IBM Business Automation Workflow Containers fixes December 2025
IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 006. IBM Cloud Pak for Business Automation could allow a local user with access to the container to execute OS system calls.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What are the main security issues addressed by CVE-2025-36059?
CVE-2025-36059 addresses multiple security vulnerabilities in various versions of IBM Business Automation Workflow Containers and IBM Cloud Pak for Business Automation.
Which versions of IBM products are affected by CVE-2025-36059?
IBM Business Automation Workflow containers versions 25.0.0 to 25.0.0 Interim Fix 002, 24.0.1 to 24.0.1 Interim Fix 005, and 24.0.0 to 24.0.0 Interim Fix 006 are affected by CVE-2025-36059.
How can I mitigate the risks associated with CVE-2025-36059?
To mitigate CVE-2025-36059, users should apply the latest patches and updates provided by IBM for the affected products.
Is CVE-2025-36059 a critical vulnerability?
The severity of CVE-2025-36059 may vary, but it is important to address it promptly to avoid potential security risks.
Where can I find more information about CVE-2025-36059?
More information about CVE-2025-36059 can be found on IBM's official support page.