Cross-Site Scripting Vulnerability in IBM Business Automation Workflow
CVE-2022-38390
5.4MEDIUM
Summary
Multiple versions of IBM Business Automation Workflow are affected by a cross-site scripting vulnerability. This issue enables users to inject arbitrary JavaScript code into the Web UI, which can manipulate the application's intended functionality. As a result, attackers may exploit this weakness to access sensitive information, including user credentials, within a trusted session. Organizations using these products should ensure they are updated to mitigate the risk associated with this vulnerability.
Affected Version(s)
Business Automation Workflow 22.0.1
Business Automation Workflow 21.0.1 < 21.0.3.1
Business Automation Workflow 20.0.0.1 < 20.0.0.2
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved