Cyber Resilience

CVE-2025-36058

Info Disclosure in Ibm Business Automation Workflow 24.0.0 … 25.0.0

Published
20 January 2026
Modified
17 February 2026
Patch / advisory
CVSS Score v3.1 5.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.0011 1th percentile
Risk Priority 35 floored blend · peak EPSS

Summary

CVE-2025-36058 is a medium-severity Insertion of Sensitive Information into Externally-Accessible File or Directory (CWE-538) vulnerability in Ibm Business Automation Workflow. Its CVSS base score is 5.5 (Medium).

Operationally, ranked at the 1th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified map to AC-3 (Access Enforcement) and AC-6 (Least Privilege) — see the control section below for these in your framework.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability Data

IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 006. IBM Cloud Pak for Business Automation and IBM Business Automation Workflow containers may disclose sensitve configuration…

more

information in a config map.

CWE(s)

Related Threats

CVEs Like This One

CVE-2024-43188Same product: Ibm Business Automation Workflow
CVE-2024-38321Same product: Ibm Business Automation Workflow
CVE-2025-13096Same product: Ibm Business Automation Workflow
CVE-2025-1495Same product: Ibm Business Automation Workflow
CVE-2023-24957Same product: Ibm Business Automation Workflow
CVE-2024-54179Same product: Ibm Business Automation Workflow
CVE-2026-1248Same product: Ibm Business Automation Workflow
CVE-2023-50947Same product: Ibm Business Automation Workflow
CVE-2025-36054Same product: Ibm Business Automation Workflow
CVE-2025-36051Same vendor: Ibm

Affected Assets

ibm
business automation workflow
24.0.0, 24.0.1, 25.0.0

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)
  • AC-3 Access Enforcement
  • AC-6 Least Privilege
  • SC-28 Protection of Information at Rest
Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)
  • 2 hardening rules · 2 OS baselines
Validate
Prove the fix (OWASP ASVS)
  • V14.1.2
  • V14.2.8

Mitigating Controls (NIST 800-53 r5) AI

prevent

Directly enforces access restrictions on the Kubernetes config map so that sensitive configuration data cannot be read by unauthorized container processes or users.

prevent

Requires least-privilege assignment so that only the minimal set of service accounts or pods are granted read access to the config map containing the sensitive IBM BAW settings.

prevent

Mandates cryptographic or other protection mechanisms for sensitive data stored at rest inside the config map, directly mitigating the disclosed configuration exposure.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.AA-05 mostly match
prevents

Least-privilege file and directory permissions directly prevent unauthorized actors from reading sensitive data placed in accessible locations.

PR.DS-01 mostly match
prevents

Protecting data-at-rest encompasses file-level access controls and encryption that stop exposure of sensitive information in externally reachable paths.

PR.PS-01 partial match
prevents

Hardened configuration baselines and ongoing config management reduce the chance that sensitive data is written to world-readable files or directories.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

prevents

By ensuring that only the minimum necessary data is present in files or directories that may be reachable by external parties, the control lowers the impact of any subsequent exposure.

mitigates

Requiring visible or metadata labels on classified information helps ensure that files placed in externally accessible locations still carry an explicit sensitivity marker, lowering the likelihood of unnoticed exposure.

mitigates

The control’s requirement to remove or securely destroy information stored in externally accessible locations reduces the risk of sensitive data being left in files or directories that external parties can reach.

none

Logging disposals, selecting vetted external disposal services, and protecting media according to classification reduce the likelihood that sensitive information ends up in externally accessible files or directories.

none

Verifying and sanitizing equipment prior to disposal or resale prevents sensitive files or directories from remaining accessible to external parties who later obtain the hardware.

References