CVE-2026-11864
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Summary
IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive application data and/or determine the structure of the XML document.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | Cloud Pak for Business Automation | 26.0.0 <= 26.0.0 Interim Fix 001 | affected |
| IBM | Cloud Pak for Business Automation | 25.0.0 <= 25.0.0 Interim Fix 005 | affected |
| IBM | Cloud Pak for Business Automation | 24.0.1 <= 24.0.1 Interim Fix 008 | affected |
| IBM | Cloud Pak for Business Automation | 24.0.0 <= 24.0.0 Interim Fix 009 | affected |
Weaknesses
- CWE-643: CWE-643 Improper Neutralization of Data within XPath Expressions ('XPath Injection')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.