Vulnerabilities > IBM > Business Automation Workflow > 18.0.0.0

DATE CVE VULNERABILITY TITLE RISK
2019-04-08 CVE-2018-1885 Information Exposure vulnerability in IBM products
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could allow an unauthenticated attacker to obtain sensitve information using a specially cracted HTTP request.
network
low complexity
ibm CWE-200
5.3
2018-12-14 CVE-2018-1848 Cross-site Scripting vulnerability in IBM products
IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2018-09-20 CVE-2018-1674 SQL Injection vulnerability in IBM products
IBM Business Process Manager 8.5 through 8.6 and 18.0.0.0 through 18.0.0.1 are vulnerable to SQL injection.
network
low complexity
ibm CWE-89
8.8