First published: Mon Apr 08 2019(Updated: )
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could reveal sensitive version information about the server from error pages that could aid an attacker in further attacks against the system. IBM X-Force ID: 154889.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Business Automation Workflow | =18.0.0.0 | |
IBM Business Automation Workflow | =18.0.0.1 | |
IBM Business Automation Workflow | =18.0.0.2 | |
IBM Business Process Manager | >=8.0.0.0<=8.0.1.3 | |
IBM Business Process Manager | >=8.5.0.0<=8.5.0.2 | |
IBM Business Process Manager | =8.5.5.0 | |
IBM Business Process Manager | =8.5.6.0 | |
IBM Business Process Manager | =8.5.6.0-cf1 | |
IBM Business Process Manager | =8.5.6.0-cf2 | |
IBM Business Process Manager | =8.5.7.0 | |
IBM Business Process Manager | =8.5.7.0-cf2017.06 | |
IBM Business Process Manager | =8.6.0.0 | |
IBM Business Process Manager | =8.6.0.0-cf2018.03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2018-1999.
The severity level of CVE-2018-1999 is medium.
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 are affected by CVE-2018-1999.
An attacker can exploit CVE-2018-1999 by using the sensitive version information revealed from error pages to launch further attacks against the system.
You can find more information about CVE-2018-1999 at the following references: [link1](https://exchange.xforce.ibmcloud.com/vulnerabilities/154889) and [link2](https://www.ibm.com/support/docview.wss?uid=ibm10870502).