CVE-2026-12730
LOWImproper Validation of Certificate with Host Mismatch in IBM Business Automation Workflow containers
Title source: cnaDescription
IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostname matches the server certificate potentially allowing connections to an attacker-controlled server.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
patch
https://www.ibm.com/support/pages/node/7282596
Scores
CVSS v3
3.8
EPSS
0.0017
EPSS Percentile
6.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-297
Status
published
Products (7)
IBM/Business Automation Workflow containers and traditional
24.0.0 - 24.0.0 Interim Fix 009
IBM/Business Automation Workflow containers and traditional
24.0.1 - 24.0.1 Interim Fix 007
IBM/Business Automation Workflow containers and traditional
25.0.0 - 25.0.0 Interim Fix 005
IBM/Business Automation Workflow containers and traditional
26.0.0
ibm/business_automation_workflow
24.0.0 (20 CPE variants)
ibm/business_automation_workflow
24.0.1 (16 CPE variants)
ibm/business_automation_workflow
25.0.0 (10 CPE variants)
Published
Aug 05, 2026
Tracked Since
Aug 05, 2026