ZeroHour

CVE-2026-12756

moderate

XXE Vulnerability in IBM Business Automation Workflow Could Leak Sensitive Files

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

IBM Business Automation Workflow, in both its containerized and traditional (on-premises) deployments, contains an XML external entity injection (XXE) flaw (CWE-611) that is triggered when the product parses attacker-supplied XML data. Because the CVSS vector requires only low privileges (PR:L), an authenticated remote attacker with valid user access can submit crafted XML containing malicious external entity definitions. Successful exploitation lets the attacker read sensitive files or data from the host (high confidentiality impact) and potentially exhaust memory resources, degrading or disrupting the service (low availability impact); integrity is not affected. All organizations running the affected container or traditional editions of Business Automation Workflow are exposed, particularly where business users can upload or submit XML content into processes or services. As of this writing there is no known public proof of concept and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Apply the fix from IBM's official security bulletin for this CVE to all Business Automation Workflow container and traditional deployments once the patched versions are confirmed. As an interim mitigation, disable or restrict DTD and external entity resolution in XML parsers handling user-supplied XML, and limit which authenticated users and integration endpoints can submit XML content. Review logs for unexpected file-read behavior or memory exhaustion on process/service nodes that ingest XML, and verify that workflow servers cannot reach arbitrary internal file paths or external DTD endpoints.

Affected
IBM Business Automation Workflow (containers)
IBM Business Automation Workflow (traditional)
Estimated exposure
moderate≈ low thousands of enterprise deployments worldwide (order-of-magnitude estimate; no public install counts exist) — Business Automation Workflow is licensed enterprise software deployed on-premises or in private cloud by large and mid-size organizations, so the installed base is far smaller than mass-market software but each deployment may serve…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.