Indirect Object Reference Vulnerability in IBM Cloud Pak for Business Automation
CVE-2025-36023

6.5MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
8 August 2025

What is CVE-2025-36023?

A vulnerability exists in IBM Cloud Pak for Business Automation that allows an authenticated user to access sensitive user and system information. This issue arises due to an indirect object reference that can be exploited through a user-controlled key, potentially leading to unauthorized exposure of data. Users of affected versions should assess their systems and consider applying security patches to mitigate this risk.

Affected Version(s)

Cloud Pak for Business Automation 24.0.0 <= 24.0.0 IF005

Cloud Pak for Business Automation 24.0.1 <= 24.0.1 IF002

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36023 : Indirect Object Reference Vulnerability in IBM Cloud Pak for Business Automation