Vulnerabilities > IBM > Business Automation Workflow > 19.0.0.3

DATE CVE VULNERABILITY TITLE RISK
2021-10-18 CVE-2021-29878 Cross-site Scripting vulnerability in IBM Business Automation Workflow
IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2021-09-29 CVE-2021-29834 Cross-site Scripting vulnerability in IBM products
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3,20.0.0.1, 20.0.0.2, and 21.0.2 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to stored cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2021-06-28 CVE-2021-29775 Cross-site Scripting vulnerability in IBM products
IBM Business Automation Workflow 19.0.03 and 20.0 and IBM Cloud Pak for Automation 20.0.3-IF002 and 21.0.1 are vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2021-02-11 CVE-2020-4768 Cross-site Scripting vulnerability in IBM Business Automation Workflow and Case Manager
IBM Case Manager 5.2 and 5.3 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2020-12-21 CVE-2020-4794 Incorrect Authorization vulnerability in IBM products
IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2, IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.6 could allow an authenticated user to obtain sensitive information or cuase a denial of service due to iimproper authorization checking.
network
low complexity
ibm CWE-863
5.4
2020-11-30 CVE-2020-4900 Information Exposure Through Log Files vulnerability in IBM Business Automation Workflow 19.0.0.3
IBM Business Automation Workflow 19.0.0.3 stores potentially sensitive information in log files that could be read by a local user.
local
low complexity
ibm CWE-532
5.5
2020-09-15 CVE-2020-4530 Cross-site Scripting vulnerability in IBM products
IBM Business Automation Workflow C.D.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 are vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2020-09-08 CVE-2020-4698 Cross-site Scripting vulnerability in IBM products
IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to stored cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2020-09-08 CVE-2020-4516 Cross-site Scripting vulnerability in IBM products
IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2020-06-17 CVE-2020-4532 Information Exposure Through an Error Message vulnerability in IBM products
IBM Business Automation Workflow and IBM Business Process Manager (IBM Business Process Manager Express 8.5.5, 8.5.6, 8.5.7, and 8.6) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.
network
low complexity
ibm CWE-209
5.3