CVE-2025-1495: IBM Business Automation Workflow missing authentication
IBM Business Automation Workflow 24.0.0 and 24.0.1 through 24.0.1 IF001 Center may leak sensitive information due to missing authorization validation.
Other sources
IBM Business Automation Workflow Center may leak sensitive information due to missing authorization validation.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1495?
CVE-2025-1495 has been rated as a high severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2025-1495?
To mitigate CVE-2025-1495, upgrade IBM Business Automation Workflow to version 24.0.2 or later, where the missing authorization validation is addressed.
What versions of IBM Business Automation Workflow are affected by CVE-2025-1495?
CVE-2025-1495 affects IBM Business Automation Workflow versions 24.0.0 and 24.0.1, including 24.0.1 IF001.
What type of information may be leaked due to CVE-2025-1495?
CVE-2025-1495 may result in the leakage of sensitive information that should be protected by proper authorization mechanisms.
Is there a workaround for CVE-2025-1495?
Currently, the recommended solution for CVE-2025-1495 is to upgrade the affected software, as there are no effective workarounds available.