CVE-2025-36054: Cross-site scripting vulnerability affect IBM Business Automation Workflow Process Federation Server -
IBM Business Automation Workflow containers 24.0.0 through 24.0.0-IF006, 24.0.1 through 24.0.1-IF004, 25.0.0 through 25.0.0-IF001 and IBM Business Automation Workflow traditional with Process Federation Server 24.0.0 through 24.0.1 and 25.0.0 are vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Business Automation Workflow is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Information
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36054?
CVE-2025-36054 is classified with a high severity due to its potential for cross-site scripting attacks.
How do I fix CVE-2025-36054?
To mitigate CVE-2025-36054, users should update IBM Business Automation Workflow to the latest patched versions.
Which versions are affected by CVE-2025-36054?
CVE-2025-36054 affects IBM Business Automation Workflow versions between 24.0.0 and 24.0.1-IF004, and 25.0.0 up to 25.0.0-IF001.
What types of attacks are possible with CVE-2025-36054?
CVE-2025-36054 allows attackers to execute arbitrary JavaScript in the context of the user's browser, leading to cross-site scripting attacks.
Is CVE-2025-36054 specific to IBM products?
Yes, CVE-2025-36054 specifically affects IBM Business Automation Workflow software and its versions listed in the vulnerability details.