ZeroHour

CVE-2026-13107

moderate

XXE in IBM Business Automation Workflow (Containers and Traditional)

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

IBM Business Automation Workflow (BAW), in both containerized and traditional deployments, may use programming model artifacts with XML parsing that is vulnerable to XML Entity Injection (XXE) by default. An attacker with authenticated, low-privilege access (CVSS vector requires PR:L) who can influence XML processed by these artifacts can inject crafted external entity declarations that the parser resolves. Successful exploitation yields high confidentiality impact — typically local file disclosure and internal network/SSF reconnaissance — plus a low availability impact such as resource-exhaustion via entity expansion; integrity is not affected. All BAW deployment styles named in the advisory are affected, and the affected version ranges were not specified in the available data. There is no known public proof of concept and the flaw is not on the CISA KEV list, so exploitation status is currently none known.

What to do: Check the IBM PSIRT security bulletin for BAW containers and traditional for patch releases and apply them as soon as fixed versions are published. Audit applications and programming model artifacts for XML processing and disable DTD/external entity resolution (e.g., disallow DOCTYPE declarations) on all XML parsers used by process applications. Restrict authenticated access to BAW authoring and runtime interfaces, and monitor logs for signs of file-disclosure or SSRF-style requests originating from the workflow server.

Affected
IBM Business Automation Workflow (containers)
IBM Business Automation Workflow (traditional)
Estimated exposure
moderatelikely low thousands of enterprise deployments (order of 1k–10k installations), most behind internal networks — IBM BAW is enterprise-licensed process automation software typically deployed on-premise or in private clouds by large organizations; no public install counts or internet-scan data exist, so this is an order-of-magnitude estimate based on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Business Automation Workflow containers and traditional may use programming model artifacts that are vulnerable to XML Entity Injection attacks by default.

Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.