CVE-2020-4900
- EPSS 0.29%
- Veröffentlicht 30.11.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:33:23
IBM Business Automation Workflow 19.0.0.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 190991.
CVE-2020-4672
- EPSS 0.56%
- Veröffentlicht 16.11.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:33:06
IBM Business Automation Workflow 20.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure w...
CVE-2020-4531
- EPSS 1.43%
- Veröffentlicht 25.09.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:32:51
IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This informatio...
CVE-2020-4530
- EPSS 0.56%
- Veröffentlicht 15.09.2020 14:15:14
- Zuletzt bearbeitet 21.11.2024 05:32:51
IBM Business Automation Workflow C.D.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionalit...
CVE-2020-4698
- EPSS 0.56%
- Veröffentlicht 08.09.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:33:08
IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended...
CVE-2020-4516
- EPSS 0.81%
- Veröffentlicht 08.09.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:32:50
IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functi...
CVE-2020-4557
- EPSS 0.56%
- Veröffentlicht 29.06.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 05:32:54
IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended fun...
CVE-2020-4532
- EPSS 1.3%
- Veröffentlicht 17.06.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:32:51
IBM Business Automation Workflow and IBM Business Process Manager (IBM Business Process Manager Express 8.5.5, 8.5.6, 8.5.7, and 8.6) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in...
CVE-2020-4490
- EPSS 0.86%
- Veröffentlicht 29.05.2020 13:15:09
- Zuletzt bearbeitet 21.11.2024 05:32:48
IBM Business Automation Workflow 18 and 19, and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redire...
CVE-2020-4446
- EPSS 0.9%
- Veröffentlicht 06.05.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:32:44
IBM Business Process Manager 8.0, 8.5, and 8.6 and IBM Business Automation Workflow 18.0 and 19.0 could allow a remote attacker to bypass security restrictions, caused by the failure to perform insufficient authorization checks. IBM X-Force ID: 18112...