CVE-2025-1838: IBM Cloud Pak for Business Automation denial of service
IBM Business Automation Workflow Authoring allows an authenticated user to bypass client-side data validation in an authoring user interface which could cause a denial of service.
Other sources
IBM Cloud Pak for Business Automation
24.0.0 and 24.0.1 through 24.0.1 IF001
Authoring allows an authenticated user to bypass client-side data validation in an authoring user interface which could cause a denial of service.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1838?
CVE-2025-1838 is categorized as a high severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2025-1838?
To mitigate CVE-2025-1838, it is recommended to upgrade IBM Cloud Pak for Business Automation to versions 24.0.1 or later.
Who is affected by CVE-2025-1838?
CVE-2025-1838 affects users of IBM Cloud Pak for Business Automation versions 24.0.0 and 24.0.1 up to 24.0.1 IF001.
What type of attack can exploit CVE-2025-1838?
CVE-2025-1838 can be exploited through bypassing client-side data validation in the authoring user interface.
Can CVE-2025-1838 be exploited remotely?
CVE-2025-1838 requires an authenticated user to exploit the vulnerability, indicating that it is not a remote attack.