CVE Vulnerabilities

CVE-2025-36091

Unverified Ownership

Published: Nov 03, 2025 | Modified: Nov 05, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause dashboards to become inaccessible to legitimate users due to invalid ownership assignment.

Weakness

The product does not properly verify that a critical resource is owned by the proper entity.

Affected Software

Name Vendor Start Version End Version
Cloud_pak_for_business_automation Ibm 24.0.0 (including) 24.0.0 (including)
Cloud_pak_for_business_automation Ibm 24.0.0-interim_fix_001 (including) 24.0.0-interim_fix_001 (including)
Cloud_pak_for_business_automation Ibm 24.0.0-interim_fix_002 (including) 24.0.0-interim_fix_002 (including)
Cloud_pak_for_business_automation Ibm 24.0.0-interim_fix_003 (including) 24.0.0-interim_fix_003 (including)
Cloud_pak_for_business_automation Ibm 24.0.0-interim_fix_004 (including) 24.0.0-interim_fix_004 (including)
Cloud_pak_for_business_automation Ibm 24.0.1 (including) 24.0.1 (including)
Cloud_pak_for_business_automation Ibm 24.0.1-interim_fix_001 (including) 24.0.1-interim_fix_001 (including)
Cloud_pak_for_business_automation Ibm 24.0.1-interim_fix_002 (including) 24.0.1-interim_fix_002 (including)
Cloud_pak_for_business_automation Ibm 24.0.1-interim_fix_004 (including) 24.0.1-interim_fix_004 (including)
Cloud_pak_for_business_automation Ibm 25.0.0 (including) 25.0.0 (including)
Cloud_pak_for_business_automation Ibm 25.0.0-interim_fix_001 (including) 25.0.0-interim_fix_001 (including)

Potential Mitigations

References