CVE-2025-36091
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-03

Last updated on: 2025-11-05

Assigner: IBM Corporation

Description
IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause dashboards to become inaccessible to legitimate users due to invalid ownership assignment.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-03
Last Modified
2025-11-05
Generated
2026-06-16
AI Q&A
2025-11-03
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 11 associated CPEs
Vendor Product Version / Range
ibm cloud_pak_for_business_automation 24.0.0
ibm cloud_pak_for_business_automation 24.0.0
ibm cloud_pak_for_business_automation 24.0.0
ibm cloud_pak_for_business_automation 24.0.0
ibm cloud_pak_for_business_automation 24.0.0
ibm cloud_pak_for_business_automation 24.0.1
ibm cloud_pak_for_business_automation 24.0.1
ibm cloud_pak_for_business_automation 24.0.1
ibm cloud_pak_for_business_automation 24.0.1
ibm cloud_pak_for_business_automation 25.0.0
ibm cloud_pak_for_business_automation 25.0.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-283 The product does not properly verify that a critical resource is owned by the proper entity.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability in IBM Cloud Pak For Business Automation versions 25.0.0, 24.0.1, and 24.0.0 allows an authenticated user to cause dashboards to become inaccessible to legitimate users by assigning invalid ownership.

Impact Analysis

The impact of this vulnerability is that legitimate users may be unable to access dashboards, potentially disrupting business operations or workflows that rely on these dashboards.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-36091. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart