CVE-2026-12756
7.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
Summary
IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | Business Automation Workflow containers and traditional | 26.0.0 <= 26.0.0 Interim Fix 001 | affected |
| IBM | Business Automation Workflow containers and traditional | 25.0.0 <= 25.0.0 Interim Fix 005 | affected |
| IBM | Business Automation Workflow containers and traditional | 24.0.1 <= 24.0.1 Interim Fix 008 | affected |
| IBM | Business Automation Workflow containers and traditional | 24.0.0 <= 24.0.0 Interim Fix 009 | affected |
Weaknesses
- CWE-611: CWE-611 Improper Restriction of XML External Entity Reference
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.