First published: Tue Aug 20 2019(Updated: )
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could allow a user to obtain highly sensitive information from another user by inserting links that would be clicked on by unsuspecting users. IBM X-Force ID: 162771.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Business Automation Workflow | >=18.0.0.0<=19.0.0.2 | |
IBM Business Process Manager | >=8.0.0.0<=8.0.1.3 | |
IBM Business Process Manager | >=8.5.0.0<=8.5.0.2 | |
IBM Business Process Manager | =8.5.5.0 | |
IBM Business Process Manager | =8.5.6.0 | |
IBM Business Process Manager | =8.5.6.0-cf01 | |
IBM Business Process Manager | =8.5.6.0-cf02 | |
IBM Business Process Manager | =8.5.7.0 | |
IBM Business Process Manager | =8.5.7.0-cf2016.06 | |
IBM Business Process Manager | =8.5.7.0-cf2016.09 | |
IBM Business Process Manager | =8.5.7.0-cf2016.12 | |
IBM Business Process Manager | =8.5.7.0-cf2017.03 | |
IBM Business Process Manager | =8.5.7.0-cf2017.06 | |
IBM Business Process Manager | =8.6.0.0 | |
IBM Business Process Manager | =8.6.0.0-cf2017.12 | |
IBM Business Process Manager | =8.6.0.0-cf2018.03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-4425 is medium with a severity value of 5.7.
A user can exploit CVE-2019-4425 by inserting links that would be clicked on by unsuspecting users to obtain highly sensitive information from another user.
IBM Business Automation Workflow versions 18.0.0.0, 18.0.0.1, and 18.0.0.2, as well as IBM Business Process Manager versions 8.0.0.0 to 8.0.1.3 and 8.5.0.0 to 8.5.0.2 are affected by CVE-2019-4425.
The X-Force ID for CVE-2019-4425 is 162771.
You can find more information about CVE-2019-4425 at the following references: [IBM X-Force](https://exchange.xforce.ibmcloud.com/vulnerabilities/162771) and [IBM Support](https://www.ibm.com/support/docview.wss?uid=ibm10959261).