CVE Vulnerabilities

CVE-2025-36058

Insertion of Sensitive Information into Externally-Accessible File or Directory

Published: Jan 20, 2026 | Modified: Feb 17, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 006. IBM Cloud Pak for Business Automation and IBM Business Automation Workflow containers may disclose sensitve configuration information in a config map.

Weakness

The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.

Affected Software

NameVendorStart VersionEnd Version
Business_automation_workflowIbm24.0.0 (including)24.0.0 (including)
Business_automation_workflowIbm24.0.0-if001 (including)24.0.0-if001 (including)
Business_automation_workflowIbm24.0.0-if002 (including)24.0.0-if002 (including)
Business_automation_workflowIbm24.0.0-if003 (including)24.0.0-if003 (including)
Business_automation_workflowIbm24.0.0-if004 (including)24.0.0-if004 (including)
Business_automation_workflowIbm24.0.0-if005 (including)24.0.0-if005 (including)
Business_automation_workflowIbm24.0.0-if006 (including)24.0.0-if006 (including)
Business_automation_workflowIbm24.0.1 (including)24.0.1 (including)
Business_automation_workflowIbm24.0.1-if001 (including)24.0.1-if001 (including)
Business_automation_workflowIbm24.0.1-if002 (including)24.0.1-if002 (including)
Business_automation_workflowIbm24.0.1-if004 (including)24.0.1-if004 (including)
Business_automation_workflowIbm24.0.1-if005 (including)24.0.1-if005 (including)
Business_automation_workflowIbm25.0.0 (including)25.0.0 (including)
Business_automation_workflowIbm25.0.0-if001 (including)25.0.0-if001 (including)
Business_automation_workflowIbm25.0.0-if002 (including)25.0.0-if002 (including)

Potential Mitigations

References