CVE-2025-36093: IBM Cloud Pak For Business Automation
High severity, CVSS 7.4. EPSS: 0.3% chance of exploitation in the next 30 days.
IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an attacker to access unauthorized content or perform unauthorized actions using man in the middle techniques due to improper access controls.
Affected products
- IBM Cloud Pak For Business Automation: version 24.0.0 only; version 24.0.1 only; version 25.0.0 only
Published 2025-11-03. Last modified 2026-06-17.