Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-12730

Gravedad CVSS v3.1:
BAJA
Tipo:
CWE-297 Validación incorrecta de certificados con host no coincidente
Fecha de publicación:
05/08/2026
Última modificación:
10/08/2026

Descripción

*** Pendiente de traducción *** IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostname matches the server certificate potentially allowing connections to an attacker-controlled server.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:-:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:-:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if001:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if001:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if002:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if002:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if003:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if003:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if004:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if004:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if005:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if005:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if006:*:*:containers:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if006:*:*:traditional:*:*:*
cpe:2.3:a:ibm:business_automation_workflow:24.0.0:if007:*:*:containers:*:*:*


Referencias a soluciones, herramientas e información