CVE-2025-36054: IBM Business Automation Workflow

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM Business Automation Workflow containers 24.0.0 through 24.0.0-IF006, 24.0.1 through 24.0.1-IF004, 25.0.0 through 25.0.0-IF001 and IBM Business Automation Workflow traditional with Process Federation Server 24.0.0 through 24.0.1 and 25.0.0 are vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Affected products

  • IBM Business Automation Workflow: affected versions not specified; version 24.0.0 only; version 24.0.1 only; version 25.0.0 only
  • IBM Process Federation Server: version 24.0.0 only; version 24.0.1 only; version 25.0.0 only

Published 2025-11-06. Last modified 2026-06-17.