IBM Support

BAMOE CVE Issues

News


Abstract

How to know if the CVE is there in the image for BAMOE 8 and BAMOE 9

Content

For BAMOE 8, there is on-prem and container for OpenShift using the operator installation.

Unfortunately there is no separate scan so both are based on the container image. Typically anything related to OS is specifically RHEL such as libssh / python. For on-prem, we know it must exist in the maven repository.zip or the .war if it is affected.

 

For the Openshift image, it can be easily checked here:

https://catalog.redhat.com/en/software/containers/ibm-bamoe/bamoe-kieserver-rhel8/62d663eeab9d2dc0099521fc#security

 

For the on-prem, it is pretty similar except the OS ones are excluded. You can also see if an CVE is fixed. For example, the latest one is BAMOE 8.0.8 as of publishing this technote:

BAMOE 8.0.8 addressed CVE:

https://www.ibm.com/support/pages/node/7241943

For other versions, it is easy to type this in google

Multiple vulnerabilities were addressed in IBM Business Automation Manager Open Editions <version number example: 8.0.8>.

 

For BAMOE 9, the CVE list can be found here:

https://quay.io/organization/bamoe

After selecting the image you like to check you can click on the "tags" tab to see what is the CVE affected there.

https://quay.io/repository/bamoe/extended-services?tab=tags

 
As of writing this BAMOE 9.3.0 is the latest version and all the resolved ones are here:

https://www.ibm.com/support/pages/security-bulletin-multiple-security-vulnerabilities-ibm-business-automation-manager-open-editions-1
 

[{"Type":"MASTER","Line of Business":{"code":"LOB76","label":"Data Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSFVHI5","label":"IBM Business Automation Manager Open Editions"},"ARM Category":[{"code":"a8m3p0000006xiYAAQ","label":"IDM"},{"code":"a8m3p000000LRw0AAG","label":"Other"}],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.0.0;8.0.1;8.0.2;8.0.3;8.0.4;8.0.5;8.0.6;8.0.7;8.0.8;8.0.9;9.0.0;9.0.1;9.1.0;9.1.1;9.2.0;9.2.1;9.3.0;9.3.1"}]

Document Information

Modified date:
14 November 2025

UID

ibm17251266