Cross-Site Scripting Vulnerability in IBM Business Automation Workflow
CVE-2020-4672
5.4MEDIUM
What is CVE-2020-4672?
IBM Business Automation Workflow 20.0.0.1 contains a vulnerability that allows for cross-site scripting (XSS). This weakness could permit attackers to inject arbitrary JavaScript code into the web application's user interface. When successfully exploited, this vulnerability may result in unauthorized actions and potentially expose sensitive user credentials during a trusted session, thereby compromising the application's security posture.
Affected Version(s)
Business Automation Workflow 20.0.0.1