IBM Business Automation Workflow
cpe:2.3:a:ibm:business_automation_workflow:*:*:*:*:*:*:*
- >= 25.0.0, <= 25.0.0-IF002
- >= 24.0.1, <= 24.0.1-IF005
- >= 24.0.0, <= 24.0.0-IF006
A vulnerability exists in IBM Business Automation Workflow containers and IBM Cloud Pak for Business Automation containers, specifically in versions 25.0.0 prior to 25.0.0 Interim Fix 002, 24.0.1 prior to 24.0.1 Interim Fix 005, and 24.0.0 prior to 24.0.0 Interim Fix 006. These containers may unintentionally expose sensitive configuration details within a config map.
Exploitation of this vulnerability could lead to the unauthorized disclosure of sensitive configuration information.
Users can upgrade to IBM Business Automation Workflow Containers version 25.0.0-IF003, 24.0.1-IF006, or 24.0.0-IF007. Instructions for downloading these versions are available on the IBM Support website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.