Vulnerabilities > IBM > Business Process Manager > 8.5.6.2

DATE CVE VULNERABILITY TITLE RISK
2020-12-21 CVE-2020-4794 Incorrect Authorization vulnerability in IBM products
IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2, IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.6 could allow an authenticated user to obtain sensitive information or cuase a denial of service due to iimproper authorization checking.
network
low complexity
ibm CWE-863
5.5
2020-09-15 CVE-2020-4530 Cross-site Scripting vulnerability in IBM products
IBM Business Automation Workflow C.D.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 are vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2020-09-08 CVE-2020-4698 Cross-site Scripting vulnerability in IBM products
IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to stored cross-site scripting.
network
ibm CWE-79
3.5
2020-09-08 CVE-2020-4516 Cross-site Scripting vulnerability in IBM products
IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2020-06-17 CVE-2020-4532 Information Exposure vulnerability in IBM products
IBM Business Automation Workflow and IBM Business Process Manager (IBM Business Process Manager Express 8.5.5, 8.5.6, 8.5.7, and 8.6) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.
network
low complexity
ibm CWE-200
5.0
2020-05-06 CVE-2020-4446 Incorrect Authorization vulnerability in IBM products
IBM Business Process Manager 8.0, 8.5, and 8.6 and IBM Business Automation Workflow 18.0 and 19.0 could allow a remote attacker to bypass security restrictions, caused by the failure to perform insufficient authorization checks.
network
low complexity
ibm CWE-863
4.0
2018-03-30 CVE-2018-1384 Cross-site Scripting vulnerability in IBM products
IBM Business Process Manager 8.6 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2018-03-30 CVE-2017-1767 Cross-site Scripting vulnerability in IBM Business Process Manager
IBM Business Process Manager 8.6 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2018-03-30 CVE-2017-1766 Incorrect Authorization vulnerability in IBM Business Process Manager
Due to incorrect authorization in IBM Business Process Manager 8.6 an attacker can claim and work on ad hoc tasks he is not assigned to.
network
low complexity
ibm CWE-863
4.0
2018-03-30 CVE-2017-1765 Information Exposure vulnerability in IBM products
IBM Business Process Manager 8.6 could allow an authenticated user with special privileges to reveal sensitive information about the application server.
network
low complexity
ibm CWE-200
4.0