CVE-2018-1997: Medium severity ibm business automation workflow vulnerability
IBM Business Automation Workflow and Business Process Manager 18.0.0.0, 18.0.0.1, and 18.0.0.2 are vulnerable to a denial of service attack. An authenticated attacker might send a specially crafted request that exhausts server-side memory. IBM X-Force ID: 154774.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-1997 vulnerability?
CVE-2018-1997 is a vulnerability in IBM Business Automation Workflow and Business Process Manager 18.0.0.0, 18.0.0.1, and 18.0.0.2 that allows an authenticated attacker to perform a denial of service attack by sending a specially crafted request that exhausts server-side memory.
Which versions of IBM Business Automation Workflow are affected by CVE-2018-1997?
IBM Business Automation Workflow versions 18.0.0.0, 18.0.0.1, and 18.0.0.2 are affected by CVE-2018-1997.
Which versions of IBM Business Process Manager are affected by CVE-2018-1997?
IBM Business Process Manager versions 8.5.5.0, 8.5.6.0, 8.5.7.0, and 8.6.0.0 are affected by CVE-2018-1997.
What is the severity of CVE-2018-1997?
The severity of CVE-2018-1997 is medium, with a CVSS score of 6.5.
How can I fix CVE-2018-1997?
To fix CVE-2018-1997, it is recommended to apply the necessary patches provided by IBM. Please refer to the IBM Security Bulletin for more information.