CVE Vulnerabilities

CVE-2019-4425

Published: Aug 20, 2019 | Modified: Dec 02, 2022
CVSS 3.x
5.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could allow a user to obtain highly sensitive information from another user by inserting links that would be clicked on by unsuspecting users. IBM X-Force ID: 162771.

Affected Software

Name Vendor Start Version End Version
Business_automation_workflow Ibm 18.0.0.0 (including) 19.0.0.2 (including)
Business_process_manager Ibm 8.0.0.0 (including) 8.0.1.3 (including)
Business_process_manager Ibm 8.5.0.0 (including) 8.5.0.2 (including)
Business_process_manager Ibm 8.5.5.0 (including) 8.5.5.0 (including)
Business_process_manager Ibm 8.5.6.0 (including) 8.5.6.0 (including)
Business_process_manager Ibm 8.5.6.0-cf01 (including) 8.5.6.0-cf01 (including)
Business_process_manager Ibm 8.5.6.0-cf02 (including) 8.5.6.0-cf02 (including)
Business_process_manager Ibm 8.5.7.0 (including) 8.5.7.0 (including)
Business_process_manager Ibm 8.5.7.0-cf2016.06 (including) 8.5.7.0-cf2016.06 (including)
Business_process_manager Ibm 8.5.7.0-cf2016.09 (including) 8.5.7.0-cf2016.09 (including)
Business_process_manager Ibm 8.5.7.0-cf2016.12 (including) 8.5.7.0-cf2016.12 (including)
Business_process_manager Ibm 8.5.7.0-cf2017.03 (including) 8.5.7.0-cf2017.03 (including)
Business_process_manager Ibm 8.5.7.0-cf2017.06 (including) 8.5.7.0-cf2017.06 (including)
Business_process_manager Ibm 8.6.0.0 (including) 8.6.0.0 (including)
Business_process_manager Ibm 8.6.0.0-cf2017.12 (including) 8.6.0.0-cf2017.12 (including)
Business_process_manager Ibm 8.6.0.0-cf2018.03 (including) 8.6.0.0-cf2018.03 (including)

References