CVE-2026-12730

IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostname matches the server certificate potentially allowing connections to an attacker-controlled server.
References
Link Resource
https://www.ibm.com/support/pages/node/7282596 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:business_automation_workflow:24.0.0:-:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:-:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if001:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if001:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if002:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if002:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if003:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if003:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if004:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if004:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if005:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if005:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if006:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if006:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if007:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if007:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if008:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if008:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if009:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if009:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.1:-:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.1:-:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.1:if001:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.1:if001:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.1:if002:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.1:if002:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.1:if003:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.1:if003:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.1:if004:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.1:if004:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.1:if005:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.1:if005:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.1:if006:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.1:if006:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.1:if007:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.1:if007:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:25.0.0:-:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:25.0.0:-:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:25.0.0:if001:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:25.0.0:if001:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:25.0.0:if002:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:25.0.0:if002:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:25.0.0:if003:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:25.0.0:if003:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:25.0.0:if004:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:25.0.0:if004:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:25.0.0:if005:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:25.0.0:if005:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:26.0.0:-:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:26.0.0:-:*:*:traditional:*:*:*

History

No history.

Information

Published : 2026-08-05 16:16

Updated : 2026-08-10 19:34


NVD link : CVE-2026-12730

Mitre link : CVE-2026-12730

CVE.ORG link : CVE-2026-12730


JSON object : View

Products Affected

ibm

  • business_automation_workflow
CWE
CWE-297

Improper Validation of Certificate with Host Mismatch