IBM Business Automation Insights unverified ownership
Published Nov 3, 2025
4.3
MEDIUMCVSS 3.1
EPSS 0.36%
Description
IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause dashboards to become inaccessible to legitimate users due to invalid ownership assignment.
Affected products
-
- Version 24.0.0StatusaffectedConstraints-
- Version 24.0.1StatusaffectedConstraints-
- Version 25.0.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| IBM | Cloud Pak For Business Automation | n/a |
|
- 24.0.0
- 24.0.0
- 24.0.0
- 24.0.0
- 24.0.0
- 24.0.1
- 24.0.1
- 24.0.1
- 24.0.1
- 25.0.0
- 25.0.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Remediation/Fixes IBM strongly recommends addressing the vulnerability now. Product(s) Version(s) number and/or range Remediation/Fix/Instructions IBM Business Automation Insights 25.0.0 Apply security fix 25.0.0-IF002 IBM Business Automation Insights 24.0.1 Apply security fix 24.0.1-IF005 IBM Business Automation Insights 24.0.0 Apply security fix 24.0.0-IF005
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-37498 Advisory
- https://www.ibm.com/support/pages/node/7249999 vendor-advisorypatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-37498 | Advisory | |
| https://www.ibm.com/support/pages/node/7249999 | vendor-advisorypatchVendor Advisory |
Change history (0)
No recorded changes yet.