CVE-2026-13107
moderateXXE in IBM Business Automation Workflow (Containers and Traditional)
IBM Business Automation Workflow (BAW), in both containerized and traditional deployments, may use programming model artifacts with XML parsing that is vulnerable to XML Entity Injection (XXE) by default. An attacker with authenticated, low-privilege access (CVSS vector requires PR:L) who can influence XML processed by these artifacts can inject crafted external entity declarations that the parser resolves. Successful exploitation yields high confidentiality impact — typically local file disclosure and internal network/SSF reconnaissance — plus a low availability impact such as resource-exhaustion via entity expansion; integrity is not affected. All BAW deployment styles named in the advisory are affected, and the affected version ranges were not specified in the available data. There is no known public proof of concept and the flaw is not on the CISA KEV list, so exploitation status is currently none known.
What to do: Check the IBM PSIRT security bulletin for BAW containers and traditional for patch releases and apply them as soon as fixed versions are published. Audit applications and programming model artifacts for XML processing and disable DTD/external entity resolution (e.g., disallow DOCTYPE declarations) on all XML parsers used by process applications. Restrict authenticated access to BAW authoring and runtime interfaces, and monitor logs for signs of file-disclosure or SSRF-style requests originating from the workflow server.
| IBM Business Automation Workflow (containers) | — |
| IBM Business Automation Workflow (traditional) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Business Automation Workflow containers and traditional may use programming model artifacts that are vulnerable to XML Entity Injection attacks by default.
- Weakness
- CWE-611
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.