Description

IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 001, 24.0.1 through 24.0.1 Interim Fix 004, 24.0.0 through 24.0.0 Interim Fix 006, and earlier unsupported releases IBM Business Automation Workflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

INFO

Published Date :

2025-11-03T21:18:09.139Z

Last Modified :

2025-11-03T21:41:45.434Z

Source :

ibm
AFFECTED PRODUCTS

The following products are affected by CVE-2025-36172 vulnerability.

Vendors Products
Ibm
  • Cloud Pak For Business Automation
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-36172.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact