CVE-2025-36094: Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for January 2026.
IBM Business Automation Insights could allow an authenticated user to cause a denial of service or corrupt existing data due to the improper validation of input length.
Other sources
IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 007 could allow an authenticated user to cause a denial of service or corrupt existing data due to the improper validation of input length.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36094?
CVE-2025-36094 is considered a significant vulnerability as it can lead to denial of service and data corruption.
How do I fix CVE-2025-36094?
To remediate CVE-2025-36094, apply the latest iFixes for IBM Cloud Pak for Business Automation.
Who is affected by CVE-2025-36094?
CVE-2025-36094 affects users of IBM Cloud Pak for Business Automation and IBM Business Automation Insights.
What impact does CVE-2025-36094 have on my system?
CVE-2025-36094 can allow authenticated users to exploit improper input validation, resulting in potential data corruption or service unavailability.
Is my version vulnerable to CVE-2025-36094?
Versions of IBM Cloud Pak for Business Automation and IBM Business Automation Insights prior to the latest iFixes are vulnerable to CVE-2025-36094.