CVE-2019-4426: XSS
Case Builder component shipped with IBM Business Automation Workflow and IBM Case Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
The Case Builder component shipped with 18.0.0.1 through 19.0.0.2 and IBM Case Manager 5.1.1 through 5.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162772.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-4426?
CVE-2019-4426 is a vulnerability in the Case Builder component shipped with IBM Business Automation Workflow and IBM Case Manager.
How severe is CVE-2019-4426?
CVE-2019-4426 has a severity value of 5.4, which is considered medium.
How does CVE-2019-4426 impact IBM Business Automation Workflow?
CVE-2019-4426 allows users to embed arbitrary JavaScript code in the Web UI of IBM Business Automation Workflow, potentially altering its intended functionality.
How does CVE-2019-4426 impact IBM Case Manager?
CVE-2019-4426 allows users to embed arbitrary JavaScript code in the Web UI of IBM Case Manager, potentially altering its intended functionality.
How can I fix CVE-2019-4426?
To fix CVE-2019-4426, apply the necessary patches provided by IBM for the affected versions of IBM Business Automation Workflow and IBM Case Manager.