Cross-Site Scripting Vulnerability in IBM Business Process Manager and Automation Workflow
CVE-2020-4516
5.4MEDIUM
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 8 September 2020
Summary
IBM Business Process Manager and Business Automation Workflow are prone to cross-site scripting vulnerabilities that enable malicious users to inject arbitrary JavaScript code into the web interface. This exploitation can manipulate the intended behavior of the application and potentially lead to the unauthorized disclosure of sensitive information like user credentials during an active session. The impacted versions include various releases from 8.5 to 20.0, making this a significant security concern for users relying on these platforms.
Affected Version(s)
Business Automation Workflow 18.0
Business Automation Workflow 19.0
Business Automation Workflow 20.0
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved