Indirect Object Reference Vulnerability in IBM Cloud Pak for Business Automation
CVE-2025-36023
6.5MEDIUM
What is CVE-2025-36023?
A vulnerability exists in IBM Cloud Pak for Business Automation that allows an authenticated user to access sensitive user and system information. This issue arises due to an indirect object reference that can be exploited through a user-controlled key, potentially leading to unauthorized exposure of data. Users of affected versions should assess their systems and consider applying security patches to mitigate this risk.
Affected Version(s)
Cloud Pak for Business Automation 24.0.0 <= 24.0.0 IF005
Cloud Pak for Business Automation 24.0.1 <= 24.0.1 IF002