Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2025-13096 is a high-severity Server-Side Request Forgery (SSRF) vulnerability affecting IBM Business Automation Workflow containers versions 24.0.0 through 25.0.0. The flaw arises from XML External Entity (XXE) injection during XML data processing, allowing remote attackers with limited privileges to access sensitive information or cause memory resource exhaustion. Exploitation requires network access and low privileges but no user interaction. While no known exploits are reported in the wild, the vulnerability poses a significant risk to confidentiality and system stability. European organizations using affected IBM workflow containers should prioritize patching once available and implement network segmentation and input validation to mitigate risk. Countries with strong IBM enterprise adoption and critical automation infrastructure, such as Germany, France, and the UK, are most likely impacted. Join the discussion | CVE Database V5 | 02/02/2026, 20:56:48 UTC Added: 02/02/2026, 23:15:14 UTC |
IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 006. IBM Cloud Pak for Business Automation and IBM Business Automation Workflow containers may disclose sensitve configuration information in a config map. Join the discussion | CVE Database V5 | 01/20/2026, 15:09:07 UTC Added: 01/20/2026, 15:20:57 UTC |
IBM Business Automation Workflow containers 24.0.0 through 24.0.0-IF006, 24.0.1 through 24.0.1-IF004, 25.0.0 through 25.0.0-IF001 and IBM Business Automation Workflow traditional with Process Federation Server 24.0.0 through 24.0.1 and 25.0.0 are vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. Join the discussion | CVE Database V5 | 11/06/2025, 14:11:49 UTC Added: 11/06/2025, 14:34:28 UTC |
Showing 1 to 3 of 3 results