Stored Cross-Site Scripting in IBM Business Process Manager and Workflow
CVE-2021-38893
6.4MEDIUM
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 21 December 2021
What is CVE-2021-38893?
IBM Business Process Manager versions 8.5 and 8.6, along with IBM Business Automation Workflow versions 18.0 to 21.0, are susceptible to a stored cross-site scripting vulnerability. This issue permits an attacker to insert arbitrary JavaScript code within the Web UI, which can modify the application's intended behavior. The consequence of this vulnerability could lead to unauthorized disclosure of user credentials during a trusted session, thereby compromising the security of sensitive data.
Affected Version(s)
Business Process Manager Standard 8.5.5
Business Process Manager Standard 8.5.7.CF201706
Business Process Manager Standard 8.5.7.CF201703