CVE-2025-36172: Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for 24.0.0-IF007, 24.0.1-IF005 and 25.0.0-IF002
IBM Business Automation Workflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36172?
The severity of CVE-2025-36172 is categorized as critical due to its potential for credential disclosure.
How do I fix CVE-2025-36172?
To fix CVE-2025-36172, update to the latest version of IBM Business Automation Workflow or IBM Cloud Pak for Business Automation that addresses this vulnerability.
Who is affected by CVE-2025-36172?
CVE-2025-36172 affects users of IBM Business Automation Workflow and specific versions of IBM Cloud Pak for Business Automation.
What type of vulnerability is CVE-2025-36172?
CVE-2025-36172 is a stored cross-site scripting (XSS) vulnerability that allows for the embedding of arbitrary JavaScript code.
What are the potential consequences of CVE-2025-36172?
The potential consequences of CVE-2025-36172 include unauthorized access and credential disclosure within trusted user sessions.