First published: Thu Dec 12 2019(Updated: )
Case Builder component shipped with IBM Business Automation Workflow and IBM Case Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Business Automation Workflow | >=19.0.0.0<=19.0.0.3 | |
IBM Business Automation Workflow | =18.0.0.0 | |
IBM Case Manager | >=5.3.0<5.3.2 | |
IBM Case Manager | =5.1.1 | |
IBM Case Manager | =5.2.0 | |
IBM Case Manager | =5.2.1 | |
<=18.0 19.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4426 is a vulnerability in the Case Builder component shipped with IBM Business Automation Workflow and IBM Case Manager.
CVE-2019-4426 has a severity value of 5.4, which is considered medium.
CVE-2019-4426 allows users to embed arbitrary JavaScript code in the Web UI of IBM Business Automation Workflow, potentially altering its intended functionality.
CVE-2019-4426 allows users to embed arbitrary JavaScript code in the Web UI of IBM Case Manager, potentially altering its intended functionality.
To fix CVE-2019-4426, apply the necessary patches provided by IBM for the affected versions of IBM Business Automation Workflow and IBM Case Manager.