Skip to Main Content
Digital Business Automation Ideas


This is an IBM Automation portal for Digital Business Automation products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Please use the following category to raise ideas for these offerings for all environments (traditional on premises, containers, on cloud):
  • Cloud Pak for Business Automation - including Business Automation Studio and App Designer, Business Automation Insights

  • Business Automation Workflow (BAW) - including BAW, Business Process Manager, Workstream Services, Business Performance Center, Advanced Case Management

  • Content Services - FileNet Content Manager

  • Content Services - Content Manager OnDemand

  • Content Services - Daeja Virtual Viewer

  • Content Services - Navigator

  • Content Services - Content Collector for Email, Sharepoint, Files

  • Content Services - Content Collector for SAP

  • Content Services - Enterprise Records

  • Content Services - Content Manager (CM8)

  • Datacap

  • Automation Document Processing

  • Automation Decision Services (ADS)

  • Operational Decision Manager

  • Robotic Process Automation

  • Robotic Process Automation with Automation Anywhere

  • Blueworks Live

  • Business Automation Manager Open Edition

  • IBM Process Mining


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.


Status Submitted
Created by Guest
Created on Sep 23, 2026

Provide a supported option to suppress or sanitize Java exception class names returned in BAW REST API exceptionType responses

Environment

Product: IBM Business Automation Workflow (BAW)

Version: 26.0.0

Database: DB2

Operating System: RHEL

Deployment: WebSphere Application Server-based BAW environment

Affected interface: BAW Workflow REST API (/rest/bpm/wle/v1/...)

Issue

The customer has identified a security information-disclosure finding during a penetration test against the BAW Workflow REST API.

When an invalid request is submitted to a BAW REST API, the error response can expose the internal Java exception class name through the exceptionType field. For example:

"exceptionType":"com.ibm.bpm.wle.api.JsonToObjectErrorException"

A representative response is:

{
  "status": "error",
  "Data": {
    "status": "error",
    "exceptionType": "com.ibm.bpm.wle.api.JsonToObjectErrorException",
    "errorNumber": "CWTBG0618E",
    "errorMessage": "CWTBG0618E: The request could not be processed successfully due to invalid input...",
    "errorMessageParameters": [...],
    "programmersDetails": null
  }
}

The customer considers the Java implementation class name exposed through exceptionType to be internal implementation information and therefore an information-disclosure risk from a security-hardening perspective.

The environment has already been verified to have:

<server-stacktrace-enabled>false</server-stacktrace-enabled>

and the effective TeamWorksConfiguration.running.xml also contains:

<server-stacktrace-enabled>false</server-stacktrace-enabled>

Furthermore, the observed response contains:

"programmersDetails": null

Therefore, server-side stack-trace information is already suppressed. The remaining concern is specifically the exceptionType field and, potentially, other implementation-specific details contained in errorMessage and errorMessageParameters.

The BAW REST API documentation defines exceptionType as the exception classname. However, there is currently no identified supported BAW configuration that allows administrators to suppress, mask, or replace this field while retaining the normal REST error handling.

 

Enhancement Requested

Provide a supported security-hardening mechanism for BAW REST APIs that allows administrators to prevent internal Java implementation details from being exposed to REST API consumers.

Ideally, the enhancement should provide a configurable option to:

Suppress the exceptionType field; or

Replace exceptionType with a generic/non-implementation-specific error type; and/or

Provide a sanitized REST error-response mode that prevents Java package/class names and other internal implementation details from being returned to clients.

The solution should preserve useful information such as the BAW error code (for example, CWTBG0618E) while allowing organizations with strict security requirements to prevent disclosure of internal implementation details.

A configuration option would be preferable so that existing applications that depend on the current REST response format are not affected by default.

The enhancement would help customers address security/pentesting requirements where exposing internal Java class names through externally accessible BAW REST APIs is considered an information-disclosure vulnerability.

Idea priority High