Executive brief
IBM Business Automation Manager Open Editions, a platform used for automating business processes and decision management, is vulnerable to a security flaw in how it handles XML data. A remote attacker with basic user privileges could exploit this to access sensitive internal information or cause a service disruption by exhausting system memory. Organizations should update to version 9.5.0 to resolve this issue.
Technical details
IBM Business Automation Manager Open Editions contains an XML External Entity (XXE) vulnerability (CWE-611) within its XML processing components. The root cause is the improper restriction of XML external entity references, allowing an attacker to submit specially crafted XML data. This is a network-based attack that requires low-level authentication (PR:L). Successful exploitation allows an attacker to read local files, conduct server-side request forgery (SSRF), or trigger a denial-of-service condition via memory exhaustion. The vulnerability is addressed in version 9.5.0.
Affected products
- IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2
Timeline
- 2026-06-30: disclosed
- 2026-06-30: advisory
- 2026-06-30: patched: Fixed in version 9.5.0