Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/ibm/Business-Automation-Workflow-containers

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2025-13096 is a high-severity Server-Side Request Forgery (SSRF) vulnerability affecting IBM Business Automation Workflow containers versions 24.0.0 through 25.0.0. The flaw arises from XML External Entity (XXE) injection during XML data processing, allowing remote attackers with limited privileges to access sensitive information or cause memory resource exhaustion. Exploitation requires network access and low privileges but no user interaction. While no known exploits are reported in the wild, the vulnerability poses a significant risk to confidentiality and system stability. European organizations using affected IBM workflow containers should prioritize patching once available and implement network segmentation and input validation to mitigate risk. Countries with strong IBM enterprise adoption and critical automation infrastructure, such as Germany, France, and the UK, are most likely impacted.

Join the discussion

IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 006. IBM Cloud Pak for Business Automation and IBM Business Automation Workflow containers may disclose sensitve configuration information in a config map.

Join the discussion

IBM Business Automation Workflow containers 24.0.0 through 24.0.0-IF006, 24.0.1 through 24.0.1-IF004, 25.0.0 through 25.0.0-IF001 and IBM Business Automation Workflow traditional with Process Federation Server 24.0.0 through 24.0.1 and 25.0.0 are vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Package: pkg:github/ibm/Business-Automation-Workflow-containers
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses