EXPOSURES › CVE-2026-13449
CVE-2026-13449
HIGH
DETAIL
SourceNVD · cve
Published2026-06-30
CVSS7.6
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-13449 ↗
SHAME 25/100
IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
▸ RECOMMENDED ACTION Patch the affected products and confirm your instances are covered.
PLAYERS IMPLICATED
DESCRIPTION
IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
AFFECTED FEDRAMP PRODUCTS · 5
| PRODUCT | STATUS |
|---|---|
| IBM Cloud for Government IBM |
Authorized |
| IBM Federal HR Cloud IBM |
Authorized |
| IBM Maximo and TRIRIGA on Cloud for U.S. Federal IBM |
Authorized |
| MaaS360 Enterprise Mobility Management IBM |
Authorized |
| SmartCloud for Government IBM |
Authorized |