Vulnerabilities > IBM > Business Automation Workflow

DATE CVE VULNERABILITY TITLE RISK
2022-03-18 CVE-2021-39046 Insufficiently Protected Credentials vulnerability in IBM products
IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 and IBM Business Process Manager 8.5 and 8.6 stores user credentials in plain clear text which can be read by a lprivileged user.
network
low complexity
ibm CWE-522
4.9
2021-12-21 CVE-2021-38893 Cross-site Scripting vulnerability in IBM products
IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 are vulnerable to stored cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2021-12-21 CVE-2021-38900 Unspecified vulnerability in IBM products
IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 could allow a privileged user to obtain highly sensitive information due to improper access controls.
network
low complexity
ibm
6.5
2021-12-17 CVE-2021-38883 Cross-site Scripting vulnerability in IBM products
IBM Business Automation Workflow 18.0, 19.0, 20,0 and 21.0 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2021-11-05 CVE-2021-29753 Cleartext Transmission of Sensitive Information vulnerability in IBM products
IBM Business Automation Workflow 18.
network
high complexity
ibm CWE-319
5.9
2021-10-22 CVE-2021-29835 Cross-site Scripting vulnerability in IBM Business Automation Workflow
IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2021-10-18 CVE-2021-29878 Cross-site Scripting vulnerability in IBM Business Automation Workflow
IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2021-09-29 CVE-2021-29834 Cross-site Scripting vulnerability in IBM products
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3,20.0.0.1, 20.0.0.2, and 21.0.2 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to stored cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2021-06-28 CVE-2021-29751 Unspecified vulnerability in IBM products
IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 could allow an authenticated user to obtain sensitive information about another user under nondefault configurations.
network
low complexity
ibm
4.3
2021-06-28 CVE-2021-29775 Cross-site Scripting vulnerability in IBM products
IBM Business Automation Workflow 19.0.03 and 20.0 and IBM Cloud Pak for Automation 20.0.3-IF002 and 21.0.1 are vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4