IBM Business Automation Workflow Containers Sensitive Information Disclosure Vulnerability

Vulnerability

A vulnerability exists in IBM Business Automation Workflow containers and IBM Cloud Pak for Business Automation containers, specifically in versions 25.0.0 prior to 25.0.0 Interim Fix 002, 24.0.1 prior to 24.0.1 Interim Fix 005, and 24.0.0 prior to 24.0.0 Interim Fix 006. These containers may unintentionally expose sensitive configuration details within a config map.

Impact

Exploitation of this vulnerability could lead to the unauthorized disclosure of sensitive configuration information.

Remediation

Users can upgrade to IBM Business Automation Workflow Containers version 25.0.0-IF003, 24.0.1-IF006, or 24.0.0-IF007. Instructions for downloading these versions are available on the IBM Support website.

Added: Jan 20, 2026, 5:11 PM
Updated: Jan 20, 2026, 5:11 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
2.5
exploitability
3.4
remediation
7.7
relevance
2.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.