Stored Cross-Site Scripting in IBM Business Process Manager and Workflow
CVE-2021-38893
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 21 December 2021
What is CVE-2021-38893?
IBM Business Process Manager versions 8.5 and 8.6, along with IBM Business Automation Workflow versions 18.0 to 21.0, are susceptible to a stored cross-site scripting vulnerability. This issue permits an attacker to insert arbitrary JavaScript code within the Web UI, which can modify the application's intended behavior. The consequence of this vulnerability could lead to unauthorized disclosure of user credentials during a trusted session, thereby compromising the security of sensitive data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Business Process Manager Standard 8.5.5
Business Process Manager Standard 8.5.7.CF201706
Business Process Manager Standard 8.5.7.CF201703
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved