Remote Security Bypass in IBM Business Automation Workflow and IBM Business Process Manager
CVE-2020-4490
5.3MEDIUM
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 29 May 2020
Summary
A vulnerability exists in IBM Business Automation Workflow and IBM Business Process Manager due to a reverse tabnabbing flaw that can permit a remote attacker to bypass security mechanisms. This exploitation potentially redirects users to malicious phishing sites, compromising the integrity of user interactions. It is imperative for users of the affected IBM products to be aware of this issue and implement necessary patches to mitigate the risk.
Affected Version(s)
Business Automation Workflow 18.0.0.0
Business Automation Workflow 19.0.0.0
Business Process Manager Advanced 8.0
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved