CVE-2020-4446

4.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
6 May 2020

Summary

IBM Business Process Manager 8.0, 8.5, and 8.6 and IBM Business Automation Workflow 18.0 and 19.0 could allow a remote attacker to bypass security restrictions, caused by the failure to perform insufficient authorization checks. IBM X-Force ID: 181126.

Affected Version(s)

Business Automation Workflow 18.0.0.0

Business Automation Workflow 19.0.0.1

Business Process Manager Standard 8.5.5

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.