5.4

CVE-2023-50947

IBM Business Automation Workflow 22.0.2, 23.0.1, and 23.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.  IBM X-Force ID:  275665.

Data is provided by the National Vulnerability Database (NVD)
IbmBusiness Automation Workflow SwEditiontraditional Version >= 19.0.0.1 <= 19.0.0.3
IbmBusiness Automation Workflow SwEditiontraditional Version >= 21.0.1 <= 21.0.3.1
IbmBusiness Automation Workflow Version20.0.0.1 SwEdition-
IbmBusiness Automation Workflow Version20.0.0.1 SwEditiontraditional
IbmBusiness Automation Workflow Version20.0.0.2 SwEdition-
IbmBusiness Automation Workflow Version20.0.0.2 SwEditiontraditional
IbmBusiness Automation Workflow Version21.0.2 SwEdition-
IbmBusiness Automation Workflow Version21.0.3 Update- SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif002 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif005 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif006 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif007 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif008 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif009 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif010 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif011 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif012 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif013 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif014 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif015 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif016 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif017 SwEditioncontainers
IbmBusiness Automation Workflow Version21.0.3 Updateif028 SwEditioncontainers
IbmBusiness Automation Workflow Version22.0.1 SwEdition-
IbmBusiness Automation Workflow Version22.0.1 SwEditiontraditional
IbmBusiness Automation Workflow Version22.0.2 SwEdition-
IbmBusiness Automation Workflow Version22.0.2 SwEditionenterprise_service_bus
IbmBusiness Automation Workflow Version22.0.2 SwEditiontraditional
IbmBusiness Automation Workflow Version23.0.1 SwEdition-
IbmBusiness Automation Workflow Version23.0.1 SwEditionenterprise_service_bus
IbmBusiness Automation Workflow Version23.0.1 SwEditiontraditional
IbmBusiness Automation Workflow Version23.0.2 SwEditionenterprise_service_bus
IbmCloud Pak For Business Automation Version >= 18.0.0 <= 18.0.2
IbmCloud Pak For Business Automation Version >= 19.0.1 <= 19.0.3
IbmCloud Pak For Business Automation Version >= 20.0.1 <= 20.0.3
IbmCloud Pak For Business Automation Version21.0.3 Update-
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_001
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_002
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_003
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_004
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_005
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_006
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_007
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_008
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_009
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_010
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_011
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_012
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_013
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_014
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_015
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_016
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_017
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_018
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_019
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_020
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_021
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_022
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_023
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_024
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_025
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_026
IbmCloud Pak For Business Automation Version21.0.3 Updateinterim_fix_028
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.11% 0.295
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
psirt@us.ibm.com 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.