CVE-2025-36093: security vulnerabilities are addressed with IBM Business Automation Insights iFixes for October 2025.
IBM Business Automation Insights could allow an attacker to access unauthorized content or perform unauthorized actions using man in the middle techniques due to improper access controls.
Other sources
IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an attacker to access unauthorized content or perform unauthorized actions using man in the middle techniques due to improper access controls.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36093?
CVE-2025-36093 has a high severity rating due to the potential for unauthorized access and actions.
How do I fix CVE-2025-36093?
To fix CVE-2025-36093, apply the security patch provided by IBM for affected versions of Business Automation Insights.
Which versions of IBM Business Automation Insights are affected by CVE-2025-36093?
CVE-2025-36093 affects IBM Business Automation Insights versions up to and including 25.0.0, 24.0.1, and 24.0.0.
What types of attacks can exploit CVE-2025-36093?
CVE-2025-36093 can be exploited through man-in-the-middle techniques due to improper access controls.
What are the consequences of exploiting CVE-2025-36093?
Exploiting CVE-2025-36093 could lead to unauthorized access to content or the execution of unauthorized actions on the affected system.