Hostname Verification Flaw in IBM Business Automation Workflow Products
CVE-2026-12730

3.8LOW

What is CVE-2026-12730?

IBM Business Automation Workflow suffers from a vulnerability where hostname validation against the server certificate is inadequately performed. This oversight may allow an attacker to intercept connections by redirecting traffic to a malicious server, posing significant risks to data integrity and confidentiality. It is crucial for users to address this issue by applying the necessary patches and ensuring secure configurations.

Affected Version(s)

Business Automation Workflow containers and traditional 26.0.0

Business Automation Workflow containers and traditional 25.0.0 <= 25.0.0 Interim Fix 005

Business Automation Workflow containers and traditional 24.0.1 <= 24.0.1 Interim Fix 007

References

CVSS V3.1

Score:
3.8
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.