IBM Business Automation Workflow
cpe:2.3:a:ibm:business_automation_workflow:*:*:*:*:*:*:*
- >= 25.0.0, <= 25.0.0-IF002
- >= 24.0.1, <= 24.0.1-IF005
- >= 24.0.0, <= 24.0.0-IF006
A vulnerability in IBM Business Automation Workflow containers, specifically in versions 25.0.0 prior to 25.0.0 Interim Fix 002, 24.0.1 prior to 24.0.1 Interim Fix 005, and 24.0.0 prior to 24.0.0 Interim Fix 006, could allow a local user with access to the container to execute operating system system calls. This issue is related to improper management of privileges, potentially enabling unauthorized execution of commands at the operating system level.
Exploitation of this vulnerability could lead to unauthorized execution of operating system commands within the affected container.
Users can upgrade to IBM Business Automation Workflow containers version 25.0.0-IF003, 24.0.1-IF006, or 24.0.0-IF007. Instructions for downloading these versions are available on the IBM Support website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.