CVE-2026-12762: Insertion of Sensitive Information into Externally-Accessible File in IBM Business Automation Insights
IBM Business Automation Insights could allow a remote attacker to obtain sensitive information exposed in manifest files.
Other sources
IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in manifest files.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Business Automation Insightsto a version that resolves this vulnerability.Fixed in 26.0.0Patch 26.0.0-IF001 - Upgrade
Upgrade
IBM Business Automation Insightsto a version that resolves this vulnerability.Fixed in 25.0.0Patch 25.0.0-IF006 - Upgrade
Upgrade
IBM Business Automation Insightsto a version that resolves this vulnerability.Fixed in 24.0.1Patch 24.0.1-IF008 - Upgrade
Upgrade
IBM Business Automation Insightsto a version that resolves this vulnerability.Fixed in 24.0.0Patch 24.0.0-IF008