4.3

CVE-2019-4045

IBM Business Automation Workflow and IBM Business Process Manager 18.0.0.0, 18.0.0.1, and 18.0.0.2 provide embedded document management features. Because of a missing restriction in an API, a client might spoof the last modified by value of a document. IBM X-Force ID: 156241.

Data is provided by the National Vulnerability Database (NVD)
IbmBusiness Automation Workflow Version >= 18.0.0.0 <= 18.0.0.2
IbmBusiness Process Manager Version >= 8.5.0.0 <= 8.5.0.2
IbmBusiness Process Manager Version8.5.5.0
IbmBusiness Process Manager Version8.5.6.0 Update-
IbmBusiness Process Manager Version8.5.6.0 Updatecf1
IbmBusiness Process Manager Version8.5.6.0 Updatecf2
IbmBusiness Process Manager Version8.5.7.0 Update-
IbmBusiness Process Manager Version8.5.7.0 Updatecf201706
IbmBusiness Process Manager Version8.6.0.0 Update-
IbmBusiness Process Manager Version8.6.0.0 Updatecf201712
IbmBusiness Process Manager Version8.6.0.0 Updatecf201803
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.13% 0.327
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
psirt@us.ibm.com 4.3 2.8 1.4
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N