CVE-2025-36058 Details
Description
IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 006. IBM Cloud Pak for Business Automation and IBM Business Automation Workflow containers may disclose sensitve configuration information in a config map.
A vulnerability exists in IBM Business Automation Workflow containers and IBM Cloud Pak for Business Automation containers, specifically in versions 25.0.0 prior to 25.0.0 Interim Fix 002, 24.0.1 prior to 24.0.1 Interim Fix 005, and 24.0.0 prior to 24.0.0 Interim Fix 006. These containers may unintentionally expose sensitive configuration details within a config map.
Users can upgrade to IBM Business Automation Workflow Containers version 25.0.0-IF003, 24.0.1-IF006, or 24.0.0-IF007. Instructions for downloading these versions are available on the IBM Support website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7256777 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-538 | Insertion of Sensitive Information into Externally-Accessible File or Directory | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm business automation workflow | 24.0.0 - 24.0.0 if001 24.0.0 if002 24.0.0 if003 24.0.0 if004 24.0.0 if005 24.0.0 if006 24.0.1 - 24.0.1 if001 24.0.1 if002 24.0.1 if004 24.0.1 if005 25.0.0 - 25.0.0 if001 25.0.0 if002 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 17, 2026 | Initial Analysis | [email protected] |
| Jan 20, 2026 | New CVE Received | [email protected] |