6.1

CVE-2022-41735

IBM Business Process Manager 21.0.1 through 21.0.3.1, 20.0.0.1 through 20.0.0.2 19.0.0.1 through 19.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.  IBM X-Force ID:  65687.

Data is provided by the National Vulnerability Database (NVD)
IbmBusiness Automation Workflow SwEditiontraditional Version >= 19.0.0.1 <= 19.0.0.3
IbmBusiness Automation Workflow SwEditiontraditional Version >= 21.0.1 <= 21.0.3.1
IbmBusiness Automation Workflow Version20.0.0.1 SwEditiontraditional
IbmBusiness Automation Workflow Version20.0.0.1 Update- SwEditioncontainers
IbmBusiness Automation Workflow Version20.0.0.2 SwEditiontraditional
IbmBusiness Automation Workflow Version20.0.0.2 Update- SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.2 Update- SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 SwEditiontraditional
IbmBusiness Automation Workflow Version21.0.3 Updateif002 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif005 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif006 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif007 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif008 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif009 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif010 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif011 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif012 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif013 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif014 SwEditioncontainers
IbmBusiness Automation Workflow Version22.0.1 SwEditiontraditional
IbmBusiness Automation Workflow Version22.0.1 Update- SwEditioncontainers
IbmBusiness Automation Workflow Version22.0.1 Updateif001 SwEditioncontainers
IbmBusiness Automation Workflow Version22.0.1 Updateif002 SwEditioncontainers
IbmBusiness Automation Workflow Version22.0.1 Updateif003 SwEditioncontainers
IbmBusiness Automation Workflow Version22.0.1 Updateif004 SwEditioncontainers
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.12% 0.316
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
psirt@us.ibm.com 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.