IBM Cloud Pak Business Automation
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in IBM Cloud Pak Business Automation.
By the Year
In 2026 there have been 2 vulnerabilities in IBM Cloud Pak Business Automation with an average score of 5.9 out of ten. Last year, in 2025 Cloud Pak Business Automation had 10 security vulnerabilities published. At the current rates, it appears that the number of vulnerabilities last year and this year may equal out. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.06.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 2 | 5.90 |
| 2025 | 10 | 5.84 |
| 2024 | 6 | 6.32 |
| 2023 | 5 | 5.46 |
| 2022 | 1 | 6.80 |
It may take a day or so for new Cloud Pak Business Automation vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent IBM Cloud Pak Business Automation Security Vulnerabilities
IBM CPBA 24.0.0-25.0.0 Input Length Validation DoS/Data Corruption
CVE-2025-36094
5.4 - Medium
- February 03, 2026
IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 007 could allow an authenticated user to cause a denial of service or corrupt existing data due to the improper validation of input length.
Improper Validation of Specified Quantity in Input
IBM Cloud Pak for Business Automation 24.x/25.x Stored XSS in Web UI
CVE-2025-36436
6.4 - Medium
- February 02, 2026
IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 007 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
XSS
IBM Cloud Pak for Business Automation 25.0.0 Web UI XSS
CVE-2025-36172
6.4 - Medium
- November 03, 2025
IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 001, 24.0.1 through 24.0.1 Interim Fix 004, 24.0.0 through 24.0.0 Interim Fix 006, and earlier unsupported releases IBM Business Automation Workflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
XSS
IBM Cloud Pak Business Automation 24-25.0.0: MITM via improper access controls
CVE-2025-36093
4.8 - Medium
- November 03, 2025
IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an attacker to access unauthorized content or perform unauthorized actions using man in the middle techniques due to improper access controls.
Client-Side Enforcement of Server-Side Security
DoS via input length in IBM Cloud Pak for Business Automation 24.0-25.0
CVE-2025-36092
6.5 - Medium
- November 03, 2025
IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause a denial of service due to the improper validation of input length.
Improper Validation of Specified Quantity in Input
IBM Cloud Pak BA <24-25> dashboards auth flaw leads to denial of access
CVE-2025-36091
4.3 - Medium
- November 03, 2025
IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause dashboards to become inaccessible to legitimate users due to invalid ownership assignment.
Unverified Ownership
IBM Cloud Pak for Business Automation 24.0.x IDOR Enables Authenticated Leak
CVE-2025-36023
6.5 - Medium
- August 08, 2025
IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF005 and 24.0.1 through 24.0.1 IF002 could allow an authenticated user to view sensitive user and system information due to an indirect object reference through a user-controlled key.
Insecure Direct Object Reference / IDOR
DoS via auth Bypass of client validation in IBM Cloud Pak BA 24.0.0-24.0.1IF001
CVE-2025-1838
6.5 - Medium
- May 03, 2025
IBM Cloud Pak for Business Automation 24.0.0 and 24.0.1 through 24.0.1 IF001 Authoring allows an authenticated user to bypass client-side data validation in an authoring user interface which could cause a denial of service.
Client-Side Enforcement of Server-Side Security
XSS in IBM Cloud Pak for Business Automation 24.0.0-24.0.1 (Web UI)
CVE-2024-41753
6.1 - Medium
- May 03, 2025
IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF004 and 24.0.1 through 24.0.1 IF001 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
XSS
IBM CBA 18.0.0-22.0.2 - Comment Task Reassign API Exposes Org Data
CVE-2024-49348
6.5 - Medium
- February 05, 2025
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 allows restricting access to organizational data to valid contexts. The fact that tasks of type comment can be reassigned via API implicitly grants access to user queries in an unexpected context.
Incorrect Privilege Assignment
IBM Cloud Pak BSA XSS in Web UI before 22.0.3
CVE-2024-52364
5.4 - Medium
- February 05, 2025
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
XSS
IBM Cloud Pak Business Automation 18-22 Stored XSS
CVE-2024-52365
5.4 - Medium
- February 05, 2025
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
XSS
IBM Cloud Pak Business Automation XSS (v18-23) Privileged UI Code exec
CVE-2024-37528
5.4 - Medium
- July 08, 2024
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, 22.0.2, 23.0.1, and 23.0.2 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 294293.
XSS
SSRF in IBM Cloud Pak for Business Automation 18.0.0-23.0.2
CVE-2024-31897
4.3 - Medium
- July 08, 2024
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, 22.0.2, 23.0.1, and 23.0.2 vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 288178.
SSRF
IBM Cloud Pak for Business Automation <=23.0.2: EM Acc. Exposes Docs
CVE-2023-50959
6.5 - Medium
- March 31, 2024
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2,19.0.1, 19.0.2, 19.0.3,20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1,2 2.0.2, 23.0.1, and 23.0.2 may allow end users to query more documents than expected from a connected Enterprise Content Management system when configured to use a system account. IBM X-Force ID: 275938.
IBM CloudPak Automation CSV Injection RCE 18.0.0-22.0.2
CVE-2023-35899
9.8 - Critical
- March 21, 2024
IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 259354.
CSV Injection
IBM Cloud Pak IdP API unauth CRUD via invalid token (before 22.0.2)
CVE-2023-38367
6.5 - Medium
- February 29, 2024
IBM Cloud Pak Foundational Services Identity Provider (idP) API (IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2) allows CRUD Operations with an invalid token. This could allow an unauthenticated attacker to view, update, delete or create an IdP configuration. IBM X-Force ID: 261130.
IBM Business Automation Workflow 22.0.2-23.0.2 XSS Vulnerability
CVE-2023-50947
5.4 - Medium
- February 04, 2024
IBM Business Automation Workflow 22.0.2, 23.0.1, and 23.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 275665.
XSS
IBM Cloud Pak BA 18.0.0-22.0.2 Sensitive Info Leakage via App Config
CVE-2023-40691
4.9 - Medium
- December 18, 2023
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 may reveal sensitive information contained in application configuration to developer and administrator users. IBM X-Force ID: 264805.
XSS in IBM Cloud Pak Business Automation Web UI <=22.0.2
CVE-2023-35024
7.6 - High
- October 14, 2023
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 258349.
XSS
IBM Business Automation Workflow XSS allows arbitrary JS in Web UI
CVE-2023-32339
6.1 - Medium
- June 27, 2023
IBM Business Automation Workflow is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 255587.
XSS
IBM Cloud Pak for Business Automation XSS in 18.0.0-22.0.2
CVE-2023-22860
5.4 - Medium
- February 27, 2023
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 244100.
XSS
IBM ICP4A AD Service 18-22 Local File Storage Vulnerability (CVE-2023-23469)
CVE-2023-23469
3.3 - Low
- February 01, 2023
IBM ICP4A - Automation Decision Services 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 244504.
IBM ICP4A - User Management System Component (IBM Cloud Pak for Business Automation V21.0.3 through V21.0.3-IF008, V21.0.2 through V21.0.2-IF009, and V21.0.1 through V21.0.1-IF007) could
CVE-2021-29859
6.8 - Medium
- May 02, 2022
IBM ICP4A - User Management System Component (IBM Cloud Pak for Business Automation V21.0.3 through V21.0.3-IF008, V21.0.2 through V21.0.2-IF009, and V21.0.1 through V21.0.1-IF007) could allow a user with physical access to the system to perform unauthorized actions or obtain sensitive information due to insufficient validation and recvocation another user logouting out. IBM X-Force ID: 206081.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for IBM Cloud Pak Business Automation or by IBM? Click the Watch button to subscribe.