Executive brief
IBM Cloud Pak for Business Automation is a business process automation platform used to manage workflows and automate enterprise operations. An authenticated attacker can exploit an XPath injection vulnerability to extract sensitive application data and determine the structure of internal XML documents, potentially exposing confidential business information.
Technical details
The vulnerability is an XPath injection flaw in IBM Cloud Pak for Business Automation that allows authenticated attackers to manipulate XPath queries used to parse XML data. The attack requires valid authentication credentials but no additional user interaction. By injecting malicious XPath expressions through application inputs, an attacker can bypass query logic, exfiltrate sensitive data from XML documents, and enumerate XML document structure. The vulnerability affects versions 24.0.0 through 24.0.1 Interim Fix 008, 25.0.0 through 25.0.0 Interim Fix 005, and 26.0.0 through 26.0.0 Interim Fix 001.
Affected products
- IBM Cloud Pak for Business Automation 24.0.0 through 24.0.1 Interim Fix 008, 25.0.0 through 25.0.0 Interim Fix 005, 26.0.0 through 26.0.0 Interim Fix 001
Timeline
- 2026-09-15: disclosed