CVE-2026-12730

LOW

Improper Validation of Certificate with Host Mismatch in IBM Business Automation Workflow containers

Title source: cna
STIX 2.1

Description

IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostname matches the server certificate potentially allowing connections to an attacker-controlled server.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory patch
https://www.ibm.com/support/pages/node/7282596

Scores

CVSS v3 3.8
EPSS 0.0017
EPSS Percentile 6.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-297
Status published
Products (7)
IBM/Business Automation Workflow containers and traditional 24.0.0 - 24.0.0 Interim Fix 009
IBM/Business Automation Workflow containers and traditional 24.0.1 - 24.0.1 Interim Fix 007
IBM/Business Automation Workflow containers and traditional 25.0.0 - 25.0.0 Interim Fix 005
IBM/Business Automation Workflow containers and traditional 26.0.0
ibm/business_automation_workflow 24.0.0 (20 CPE variants)
ibm/business_automation_workflow 24.0.1 (16 CPE variants)
ibm/business_automation_workflow 25.0.0 (10 CPE variants)
Published Aug 05, 2026
Tracked Since Aug 05, 2026