First published: Mon Apr 08 2019(Updated: )
IBM Business Automation Workflow and IBM Business Process Manager 18.0.0.0, 18.0.0.1, and 18.0.0.2 provide embedded document management features. Because of a missing restriction in an API, a client might spoof the last modified by value of a document. IBM X-Force ID: 156241.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Business Automation Workflow | >=18.0.0.0<=18.0.0.2 | |
IBM Business Process Manager | >=8.5.0.0<=8.5.0.2 | |
IBM Business Process Manager | =8.5.5.0 | |
IBM Business Process Manager | =8.5.6.0 | |
IBM Business Process Manager | =8.5.6.0-cf1 | |
IBM Business Process Manager | =8.5.6.0-cf2 | |
IBM Business Process Manager | =8.5.7.0 | |
IBM Business Process Manager | =8.5.7.0-cf201706 | |
IBM Business Process Manager | =8.6.0.0 | |
IBM Business Process Manager | =8.6.0.0-cf201712 | |
IBM Business Process Manager | =8.6.0.0-cf201803 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4045 is a vulnerability in IBM Business Automation Workflow and IBM Business Process Manager 18.0.0.0, 18.0.0.1, and 18.0.0.2 that allows a client to spoof the last modified by value of a document.
CVE-2019-4045 has a severity score of 4.3, which is considered medium.
IBM Business Automation Workflow versions 18.0.0.0, 18.0.0.1, and 18.0.0.2, as well as IBM Business Process Manager versions 8.5.0.0 to 8.5.0.2 and 8.5.5.0 to 8.6.0.0, are affected by CVE-2019-4045.
The IBM X-Force ID for CVE-2019-4045 is 156241.
You can find more information about CVE-2019-4045 in the IBM Security Bulletin provided by IBM.