CVE-2018-1674: SQL Injection
IBM Business Process Manager 8.5 through 8.6 and 18.0.0.0 through 18.0.0.1 are vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 145109.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1674?
The severity of CVE-2018-1674 is high with a severity value of 8.8.
How does CVE-2018-1674 affect IBM Business Process Manager?
CVE-2018-1674 affects IBM Business Process Manager versions 8.5 through 8.6 and 18.0.0.0 through 18.0.0.1.
What is the risk of CVE-2018-1674?
CVE-2018-1674 is a SQL injection vulnerability that allows a remote attacker to view, add, modify, or delete information in the back-end database.
How can I fix CVE-2018-1674?
To fix CVE-2018-1674, apply the necessary security patches provided by IBM or upgrade to a non-vulnerable version of IBM Business Process Manager.
Where can I find more information about CVE-2018-1674?
You can find more information about CVE-2018-1674 on the following websites: SecurityTracker, IBM X-Force, and IBM Support.