CVE-2019-4149

MEDIUM

IBM Business Automation Workflow 18.0.0.0-18.0.0.2 and Business Process Manager - Stored Cross-Site Scripting

Title source: llm
STIX 2.1

Description

IBM Business Automation Workflow V18.0.0.0 through V18.0.0.2 and IBM Business Process Manager V8.6.0.0 through V8.6.0.0 Cumulative Fix 2018.03, V8.5.7.0 through V8.5.7.0 Cumulative Fix 2017.06, and V8.5.6.0 through V8.5.6.0 CF2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158415.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://www.ibm.com/support/docview.wss?uid=ibm10885104
VDB Entry, Vendor Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/158415

Scores

CVSS v3 5.4
EPSS 0.0068
EPSS Percentile 48.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (4)
ibm/business_automation_workflow 18.0.0.0 - 18.0.0.2
ibm/business_process_manager 8.5.6.0 (3 CPE variants)
ibm/business_process_manager 8.5.7.0 (2 CPE variants)
ibm/business_process_manager 8.6.0.0 (3 CPE variants)
Published Sep 05, 2019
Tracked Since Feb 18, 2026