CVE-2025-36436: Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for January 2026.
IBM Business Automation Workflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 007 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36436?
CVE-2025-36436 has been classified as having a medium severity due to its potential impact on application security.
How do I fix CVE-2025-36436?
To mitigate CVE-2025-36436, users should apply the latest iFixes for IBM Cloud Pak for Business Automation.
Who is affected by CVE-2025-36436?
CVE-2025-36436 affects users of IBM Business Automation Workflow and IBM Cloud Pak for Business Automation versions specified in the vulnerability report.
What type of vulnerability is CVE-2025-36436?
CVE-2025-36436 is a stored cross-site scripting (XSS) vulnerability that allows authenticated users to inject arbitrary JavaScript code into the Web UI.
When was CVE-2025-36436 disclosed?
CVE-2025-36436 was disclosed as part of the January 2026 iFixes for IBM Cloud Pak for Business Automation.