Skip to Main Content
Digital Business Automation Ideas


This is an IBM Automation portal for Digital Business Automation products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Please use the following category to raise ideas for these offerings for all environments (traditional on premises, containers, on cloud):
  • Cloud Pak for Business Automation - including Business Automation Studio and App Designer, Business Automation Insights

  • Business Automation Workflow (BAW) - including BAW, Business Process Manager, Workstream Services, Business Performance Center, Advanced Case Management

  • Content Services - FileNet Content Manager

  • Content Services - Content Manager OnDemand

  • Content Services - Daeja Virtual Viewer

  • Content Services - Navigator

  • Content Services - Content Collector for Email, Sharepoint, Files

  • Content Services - Content Collector for SAP

  • Content Services - Enterprise Records

  • Content Services - Content Manager (CM8)

  • Datacap

  • Automation Document Processing

  • Automation Decision Services (ADS)

  • Operational Decision Manager

  • Robotic Process Automation

  • Robotic Process Automation with Automation Anywhere

  • Blueworks Live

  • Business Automation Manager Open Edition

  • IBM Process Mining


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.


Status Under review
Created by Guest
Created on Feb 17, 2026

Mask or Disable Version Disclosure in /DecisionService Root Endpoint

Currently, sending a simple unauthenticated GET request to the root context of the Decision Service (e.g., https://[Server]/DecisionService) returns a plain HTML page displaying the full product name, version number, and specific build level (e.g., "Decision Server 9.5.0.0", "Build #IF003 on 2025-08-07").

This proposal requests the introduction of a configurable security setting (e.g., a JVM property, property file setting, or WebSphere environment variable) that allows administrators to suppress this verbose server header information. When enabled, the root endpoint should either return a generic "403 Forbidden" message, a blank page, or a minimal generic response that does not disclose the technology stack version.

Idea priority Medium
  • Guest
    Feb 23, 2026

    Out of the box, in the On Premise product, the Hosted Transparent Decision Service web application (hosted by default on /DecisionService context root) is not secured, so this root page displays the information indeed, and everyone can use the run.jsp page as well to test Decision Services.
    Securing that run.jsp page is a usual concern, and securing it can be done at the application server level or using proxies / network stacks, in that case it could be worth securing the root page the same way.
    On other product offers, like ODM on Containers or ODM on Cloud, off course there are solutions to secure the URLs, but they are different. Can you confirm which offer is to consider ?