CVE-2025-36091
MEDIUMDescription
IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause dashboards to become inaccessible to legitimate users due to invalid ownership assignment.
Is your site exposed to CVE-2025-36091?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| ibm | cloud_pak_for_business_automation |
| ibm | cloud_pak_for_business_automation |
| ibm | cloud_pak_for_business_automation |
| ibm | cloud_pak_for_business_automation |
| ibm | cloud_pak_for_business_automation |
| ibm | cloud_pak_for_business_automation |
| ibm | cloud_pak_for_business_automation |
| ibm | cloud_pak_for_business_automation |
| ibm | cloud_pak_for_business_automation |
| ibm | cloud_pak_for_business_automation |
| ibm | cloud_pak_for_business_automation |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-36091? +
How severe is CVE-2025-36091? +
What products are affected by CVE-2025-36091? +
How do I check if I'm vulnerable to CVE-2025-36091? +
Related Vulnerabilities
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to …
Dell ThinOS 10, versions prior to 2508_10.0127, contains an Unverified Ownership vulnerability. A local low-privileged attacker could potentially exploit this …
TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4.50 …
Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-ATO) vulnerability existed in Chatwoot's authentication …
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the POST /api/v1/models/import endpoint …
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally …