Information Disclosure in IBM Business Automation Workflow
CVE-2022-35279

4.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
3 November 2022

Summary

IBM Business Automation Workflow versions 18.0.0.0 to 22.0.1 are susceptible to an information disclosure vulnerability. This flaw allows authenticated users to access sensitive version information that might be exploited for further attacks on the system, posing a risk to the integrity and security of the application. It is crucial for users to address this vulnerability to ensure system protection and mitigate potential threats.

Affected Version(s)

IBM Business Automation Workflow "18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3, 20.0.0.1, 20.0.0.2, 21.0.2, 21.0.3, and 22.0.1"

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.