CVE-2026-12730: Improper Validation of Certificate with Host Mismatch in IBM Business Automation Workflow containers
IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostname matches the server certificate potentially allowing connections to an attacker-controlled server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Business Automation Workflow containersto a version that resolves this vulnerability.Fixed in 26.0.0Patch 26.0.0-IF001 - Upgrade
Upgrade
IBM Business Automation Workflow traditionalto a version that resolves this vulnerability.Fixed in 26.0.0Patch 26.0.0-IF001 - Upgrade
Upgrade
IBM Business Automation Workflow containersto a version that resolves this vulnerability.Fixed in 25.0.0 - V25.0.0-IF005Patch 25.0.0-IF006 - Upgrade
Upgrade
IBM Business Automation Workflow traditionalto a version that resolves this vulnerability.Fixed in 25.0.0 - V25.0.0-IF005Patch 25.0.0-IF006 - Upgrade
Upgrade
IBM Business Automation Workflow containersto a version that resolves this vulnerability.Fixed in 24.0.1 - V24.0.1-IF007Patch 24.0.1-IF008 - Upgrade
Upgrade
IBM Business Automation Workflow traditionalto a version that resolves this vulnerability.Fixed in 24.0.1 - V24.0.1-IF007Patch 24.0.1-IF008 - Upgrade
Upgrade
IBM Business Automation Workflow containersto a version that resolves this vulnerability.Fixed in 24.0.0 - V24.0.0-IF009Patch 24.0.0-IF010 - Upgrade
Upgrade
IBM Business Automation Workflow traditionalto a version that resolves this vulnerability.Fixed in 24.0.0 - V24.0.0-IF009Patch 24.0.0-IF010
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12730?
The severity of CVE-2026-12730 is low with a score of 3.8.
How does CVE-2026-12730 affect IBM Business Automation Workflow containers?
CVE-2026-12730 affects IBM Business Automation Workflow containers by improperly validating the hostname against the server certificate.
Which versions are impacted by CVE-2026-12730?
CVE-2026-12730 affects IBM Business Automation Workflow versions 26.0.0, 25.0.0 through Interim Fix 005, 24.0.1 through Interim Fix 007, and 24.0.0 through Interim Fix 009.
How can I mitigate the risks associated with CVE-2026-12730?
To mitigate the risks of CVE-2026-12730, ensure that your deployment of IBM Business Automation Workflow is updated to a fixed version that addresses the hostname validation issue.
Is user interaction required to exploit CVE-2026-12730?
No, user interaction is not required to exploit CVE-2026-12730.