Remote Security Bypass in IBM Business Automation Workflow and IBM Business Process Manager
CVE-2020-4490

5.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
29 May 2020

Summary

A vulnerability exists in IBM Business Automation Workflow and IBM Business Process Manager due to a reverse tabnabbing flaw that can permit a remote attacker to bypass security mechanisms. This exploitation potentially redirects users to malicious phishing sites, compromising the integrity of user interactions. It is imperative for users of the affected IBM products to be aware of this issue and implement necessary patches to mitigate the risk.

Affected Version(s)

Business Automation Workflow 18.0.0.0

Business Automation Workflow 19.0.0.0

Business Process Manager Advanced 8.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.