First published: Mon Apr 08 2019(Updated: )
IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 154890.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Business Automation Workflow | =18.0.0.0 | |
IBM Business Automation Workflow | =18.0.0.1 | |
IBM Business Process Manager | =8.6.0.0-cf2017.12 | |
IBM Business Process Manager | =8.6.0.0-cf2018.03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2018-2000.
The severity level of CVE-2018-2000 is high.
IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1, as well as IBM Business Process Manager 8.6.0.0 with CF2017.12 and CF2018.03 are affected by this vulnerability.
Cross-site request forgery is a type of attack where a malicious website tricks a user's browser into taking unwanted actions on a trusted website.
To fix CVE-2018-2000, it is recommended to apply the necessary patches or updates provided by IBM. Additionally, implementing web application firewalls and using anti-CSRF tokens can help mitigate the risk of cross-site request forgery attacks.