SQL Injection Vulnerability in IBM Business Process Manager and Automation Workflow
CVE-2019-4669
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 27 February 2020
What is CVE-2019-4669?
The vulnerability allows remote attackers to exploit improper input validation in IBM Business Process Manager and IBM Business Automation Workflow. By injecting specially crafted SQL statements, an attacker could gain unauthorized access to the back-end database, enabling them to view, add, modify, or delete critical information. The affected versions include specific builds of IBM Business Process Manager and IBM Business Automation Workflow, making it crucial for users to apply necessary patches to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Business Automation Workflow 18.0.0.1
Business Automation Workflow 19.0.0.3
Business Process Manager 8.6.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved