Multiple IBM Business Automation Workflow versions are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 233978.
2022-11-17T17:15:10.127
2024-11-21T07:16:22.870
Modified
CVSSv3.1: 5.4 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | business_automation_workflow | ≤ 18.0.0.2 | Yes |
Application | ibm | business_automation_workflow | ≤ 19.0.0.3 | Yes |
Application | ibm | business_automation_workflow | ≤ 21.0.3.1 | Yes |
Application | ibm | business_automation_workflow | 20.0.0.1 | Yes |
Application | ibm | business_automation_workflow | 20.0.0.2 | Yes |
Application | ibm | business_automation_workflow | 22.0.1 | Yes |