CVE-2019-4149
MEDIUMIBM Business Automation Workflow 18.0.0.0-18.0.0.2 and Business Process Manager - Stored Cross-Site Scripting
Title source: llmDescription
IBM Business Automation Workflow V18.0.0.0 through V18.0.0.2 and IBM Business Process Manager V8.6.0.0 through V8.6.0.0 Cumulative Fix 2018.03, V8.5.7.0 through V8.5.7.0 Cumulative Fix 2017.06, and V8.5.6.0 through V8.5.6.0 CF2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158415.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://www.ibm.com/support/docview.wss?uid=ibm10885104
VDB Entry, Vendor Advisory vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/158415
Scores
CVSS v3
5.4
EPSS
0.0068
EPSS Percentile
48.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (4)
ibm/business_automation_workflow
18.0.0.0 - 18.0.0.2
ibm/business_process_manager
8.5.6.0 (3 CPE variants)
ibm/business_process_manager
8.5.7.0 (2 CPE variants)
ibm/business_process_manager
8.6.0.0 (3 CPE variants)
Published
Sep 05, 2019
Tracked Since
Feb 18, 2026