CVE-2026-12730

EUVD-2026-53437
IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostname matches the server certificate potentially allowing connections to an attacker-controlled server.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.8 LOW
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 1.11%
Affected Products (NVD)
VendorProductVersion
ibmbusiness_automation_workflow
24.0.0
ibmbusiness_automation_workflow
24.0.0:if001
ibmbusiness_automation_workflow
24.0.0:if002
ibmbusiness_automation_workflow
24.0.0:if003
ibmbusiness_automation_workflow
24.0.0:if004
ibmbusiness_automation_workflow
24.0.0:if005
ibmbusiness_automation_workflow
24.0.0:if006
ibmbusiness_automation_workflow
24.0.0:if007
ibmbusiness_automation_workflow
24.0.0:if008
ibmbusiness_automation_workflow
24.0.0:if009
ibmbusiness_automation_workflow
24.0.1
ibmbusiness_automation_workflow
24.0.1:if001
ibmbusiness_automation_workflow
24.0.1:if002
ibmbusiness_automation_workflow
24.0.1:if003
ibmbusiness_automation_workflow
24.0.1:if004
ibmbusiness_automation_workflow
24.0.1:if005
ibmbusiness_automation_workflow
24.0.1:if006
ibmbusiness_automation_workflow
24.0.1:if007
ibmbusiness_automation_workflow
25.0.0
ibmbusiness_automation_workflow
25.0.0:if001
ibmbusiness_automation_workflow
25.0.0:if002
ibmbusiness_automation_workflow
25.0.0:if003
ibmbusiness_automation_workflow
25.0.0:if004
ibmbusiness_automation_workflow
25.0.0:if005
ibmbusiness_automation_workflow
26.0.0
𝑥
= Vulnerable software versions