IBM Business Automation Workflow Containers Privilege Escalation Vulnerability

Vulnerability

A vulnerability in IBM Business Automation Workflow containers, specifically in versions 25.0.0 prior to 25.0.0 Interim Fix 002, 24.0.1 prior to 24.0.1 Interim Fix 005, and 24.0.0 prior to 24.0.0 Interim Fix 006, could allow a local user with access to the container to execute operating system system calls. This issue is related to improper management of privileges, potentially enabling unauthorized execution of commands at the operating system level.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of operating system commands within the affected container.

Remediation

Users can upgrade to IBM Business Automation Workflow containers version 25.0.0-IF003, 24.0.1-IF006, or 24.0.0-IF007. Instructions for downloading these versions are available on the IBM Support website.

Added: Jan 20, 2026, 5:06 PM
Updated: Jan 20, 2026, 5:06 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
7.5
exploitability
3.8
remediation
7.7
relevance
2.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.