5.7

CVE-2019-4425

IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could allow a user to obtain highly sensitive information from another user by inserting links that would be clicked on by unsuspecting users. IBM X-Force ID: 162771.

Data is provided by the National Vulnerability Database (NVD)
IbmBusiness Automation Workflow Version >= 18.0.0.0 <= 19.0.0.2
IbmBusiness Process Manager Version >= 8.0.0.0 <= 8.0.1.3
IbmBusiness Process Manager Version >= 8.5.0.0 <= 8.5.0.2
IbmBusiness Process Manager Version8.5.5.0
IbmBusiness Process Manager Version8.5.6.0 Update-
IbmBusiness Process Manager Version8.5.6.0 Updatecf01
IbmBusiness Process Manager Version8.5.6.0 Updatecf02
IbmBusiness Process Manager Version8.5.7.0 Update-
IbmBusiness Process Manager Version8.5.7.0 Updatecf2016.06
IbmBusiness Process Manager Version8.5.7.0 Updatecf2016.09
IbmBusiness Process Manager Version8.5.7.0 Updatecf2016.12
IbmBusiness Process Manager Version8.5.7.0 Updatecf2017.03
IbmBusiness Process Manager Version8.5.7.0 Updatecf2017.06
IbmBusiness Process Manager Version8.6.0.0 Update- SwEdition-
IbmBusiness Process Manager Version8.6.0.0 Updatecf2017.12 SwEdition-
IbmBusiness Process Manager Version8.6.0.0 Updatecf2018.03 SwEdition-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.28% 0.481
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.7 2.1 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:P/I:N/A:N
psirt@us.ibm.com 5.7 2.1 3.6
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N