CVE-2025-36091: IBM Business Automation Insights unverified ownership
IBM Business Automation Insights could allow an authenticated user to cause dashboards to become inaccessible to legitimate users due to invalid ownership assignment.
Other sources
IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause dashboards to become inaccessible to legitimate users due to invalid ownership assignment.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36091?
CVE-2025-36091 has a medium severity level, indicating that it may allow unauthorized access to dashboards.
How do I fix CVE-2025-36091?
To fix CVE-2025-36091, apply the security patches provided by IBM for the affected versions of Business Automation Insights.
Which versions of IBM Business Automation Insights are affected by CVE-2025-36091?
CVE-2025-36091 affects IBM Business Automation Insights versions up to and including 25.0.0, 24.0.1, and 24.0.0.
What impact does CVE-2025-36091 have on users?
CVE-2025-36091 can cause dashboards to become inaccessible to legitimate users due to incorrect ownership assignments.
Is CVE-2025-36091 exploitable by unauthenticated users?
No, CVE-2025-36091 requires an authenticated user to exploit the vulnerability.