CVE-2026-12752
moderateXXE Flaw in IBM Business Automation Workflow Can Leak Sensitive Files
IBM Business Automation Workflow (both container and traditional deployments) is vulnerable to XML external entity injection (XXE) when it processes XML data. A remote attacker with low-privileged access to the product's XML-processing endpoints can craft malicious XML containing external entity references, which the server resolves. Successful exploitation allows the attacker to read sensitive files or data accessible to the application and to consume memory resources, potentially causing denial of service. The flaw is rated high severity with a CVSS 3.1 base score of 7.1, reflecting high confidentiality impact and low availability impact, but no integrity impact. No public proof-of-concept code is known and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation in the wild is not currently observed.
What to do: Check IBM's security bulletin for this CVE to identify the exact affected versions and apply the vendor's fixes or interim fixes as soon as they are available. In the meantime, disable DTD processing and external entity resolution in the XML parsers used by BAW workflows and integrations, and restrict network access to XML-processing endpoints so only authenticated, trusted users and systems can reach them. Review logs for signs of file-read or SSRF-style behavior from XML inputs and monitor memory usage for unexplained consumption.
| IBM Business Automation Workflow (containers and traditional) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resource.
- Weakness
- CWE-611
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.