8.8

CVE-2022-42435

IBM Business Automation Workflow 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, and 22.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 238054.

Data is provided by the National Vulnerability Database (NVD)
IbmBusiness Automation Workflow Version18.0.0
IbmBusiness Automation Workflow Version18.0.1
IbmBusiness Automation Workflow Version18.0.2
IbmBusiness Automation Workflow Version19.0.1
IbmBusiness Automation Workflow Version19.0.2
IbmBusiness Automation Workflow Version19.0.3
IbmBusiness Automation Workflow Version20.0.1
IbmBusiness Automation Workflow Version20.0.2
IbmBusiness Automation Workflow Version20.0.3
IbmBusiness Automation Workflow Version21.0.1
IbmBusiness Automation Workflow Version21.0.1 Updateif001
IbmBusiness Automation Workflow Version21.0.1 Updateif002
IbmBusiness Automation Workflow Version21.0.1 Updateif003
IbmBusiness Automation Workflow Version21.0.1 Updateif004
IbmBusiness Automation Workflow Version21.0.1 Updateif005
IbmBusiness Automation Workflow Version21.0.1 Updateif006
IbmBusiness Automation Workflow Version21.0.1 Updateif007
IbmBusiness Automation Workflow Version21.0.2
IbmBusiness Automation Workflow Version21.0.2 Updateif001
IbmBusiness Automation Workflow Version21.0.2 Updateif002
IbmBusiness Automation Workflow Version21.0.2 Updateif003
IbmBusiness Automation Workflow Version21.0.2 Updateif004
IbmBusiness Automation Workflow Version21.0.2 Updateif005
IbmBusiness Automation Workflow Version21.0.2 Updateif006
IbmBusiness Automation Workflow Version21.0.2 Updateif007
IbmBusiness Automation Workflow Version21.0.2 Updateif008
IbmBusiness Automation Workflow Version21.0.2 Updateif009
IbmBusiness Automation Workflow Version21.0.2 Updateif010
IbmBusiness Automation Workflow Version21.0.2 Updateif011
IbmBusiness Automation Workflow Version21.0.2 Updateif012
IbmBusiness Automation Workflow Version21.0.3
IbmBusiness Automation Workflow Version21.0.3 Updateif001
IbmBusiness Automation Workflow Version21.0.3 Updateif002
IbmBusiness Automation Workflow Version21.0.3 Updateif003
IbmBusiness Automation Workflow Version21.0.3 Updateif004
IbmBusiness Automation Workflow Version21.0.3 Updateif005
IbmBusiness Automation Workflow Version21.0.3 Updateif006
IbmBusiness Automation Workflow Version21.0.3 Updateif007
IbmBusiness Automation Workflow Version21.0.3 Updateif008
IbmBusiness Automation Workflow Version21.0.3 Updateif009
IbmBusiness Automation Workflow Version21.0.3 Updateif010
IbmBusiness Automation Workflow Version21.0.3 Updateif011
IbmBusiness Automation Workflow Version21.0.3 Updateif012
IbmBusiness Automation Workflow Version21.0.3 Updateif013
IbmBusiness Automation Workflow Version21.0.3 Updateif014
IbmBusiness Automation Workflow Version21.0.3 Updateif015
IbmBusiness Automation Workflow Version22.0.1
IbmBusiness Automation Workflow Version22.0.1 Updateif001
IbmBusiness Automation Workflow Version22.0.1 Updateif002
IbmBusiness Automation Workflow Version22.0.1 Updateif003
IbmBusiness Automation Workflow Version22.0.1 Updateif004
IbmBusiness Automation Workflow Version22.0.1 Updateif005
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.138
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
psirt@us.ibm.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.