Security Bulletin: A remote code execution vulnerability affect IBM Business Automation Workflow – CVE-2025-27363

Vulnerability Details

Basic Information

Title Security Bulletin: A remote code execution vulnerability affect IBM Business Automation Workflow – CVE-2025-27363
Type ibm
Published 2025-05-03T06:08:40
Last Seen 2025-05-03T10:56:45
CVSS Score 8.1 (HIGH)

CVSS v3 Details

Attack Vector NETWORK
Attack Complexity HIGH
Privileges Required NONE
User Interaction NONE
Scope UNCHANGED
Confidentiality Impact HIGH
Integrity Impact HIGH
Availability Impact HIGH

CVE Information

CVE IDs CVE-2025-27363
CWE
Bulletin Family software

Description

## Summary

IBM Business Automation Workflow containers package a vulnerable version of freetype.

## Vulnerability Details

**CVEID:**CVE-2025-27363
**DESCRIPTION:** An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.
**CWE:**CWE-787: Out-of-bounds Write
**CVSS Source:** [email protected]
**CVSS Base score:** 8.1
**CVSS Vector:**(CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)

## Affected Products and Versions

Affected Product(s)| Version(s)| Status
—|—|—
IBM Business Automation Workflow containers| V24.0.1 – V24.0.1-IF001
V24.0.0 – V24.0.0-IF004
earlier unsupported versions | affected

For earlier and unsupported versions of the products, IBM recommends upgrading to a fixed, supported version of the product.

## Remediation/Fixes

Affected Product(s)| Version(s)| Remediation / Fix
—|—|—
IBM Business Automation Workflow containers| V24.0.1 – V24.0.1-IF001| Apply 24.0.1-IF002
IBM Business Automation Workflow containers| V24.0.0 – V24.0.0-IF004| Apply 24.0.0-IF005
IBM Business Automation Workflow containers| earlier unsupported versions| Upgrade to 24.0.0-IF005 (or later) or 24.0.1-IF002 (or later)

## Workarounds and Mitigations

None

##

Impact Assessment

Base Score 8.1
Severity HIGH

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.