Cross-Site Scripting Vulnerability in IBM Business Process Manager and Automation Workflow
CVE-2020-4516
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 8 September 2020
What is CVE-2020-4516?
IBM Business Process Manager and Business Automation Workflow are prone to cross-site scripting vulnerabilities that enable malicious users to inject arbitrary JavaScript code into the web interface. This exploitation can manipulate the intended behavior of the application and potentially lead to the unauthorized disclosure of sensitive information like user credentials during an active session. The impacted versions include various releases from 8.5 to 20.0, making this a significant security concern for users relying on these platforms.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Business Automation Workflow 18.0
Business Automation Workflow 19.0
Business Automation Workflow 20.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved