Cross-Site Scripting Vulnerability in IBM Business Automation Workflow
CVE-2022-38390

5.4MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
17 November 2022

Summary

Multiple versions of IBM Business Automation Workflow are affected by a cross-site scripting vulnerability. This issue enables users to inject arbitrary JavaScript code into the Web UI, which can manipulate the application's intended functionality. As a result, attackers may exploit this weakness to access sensitive information, including user credentials, within a trusted session. Organizations using these products should ensure they are updated to mitigate the risk associated with this vulnerability.

Affected Version(s)

Business Automation Workflow 22.0.1

Business Automation Workflow 21.0.1 < 21.0.3.1

Business Automation Workflow 20.0.0.1 < 20.0.0.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.