CyberRota Analysis
AI-GeneratedIBM Business Automation Workflow versions 26.0.0, 25.0.0 (up to Interim Fix 005), and 24.0.1 (up to Interim Fix 007) are vulnerable due to improper hostname verification against server certificates. This flaw could enable an attacker to intercept connections by presenting a malicious server, potentially leading to unauthorized access or data exposure. Organizations using these specific versions should prioritize patching to mitigate the risk of man-in-the-middle attacks.
Original NVD Description
IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostname matches the server certificate potentially allowing connections to an attacker-controlled server.
Related CVEs
Other vulnerabilities affecting the same vendor(s)