CVE-2019-4669: SQL Injection
IBM Business Process Manager 8.5.7.0 through 8.5.7.0 2017.06, 8.6.0.0 through 8.6.0.0 CF2018.03, and IBM Business Automation Workflow 18.0.0.1 through 19.0.0.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 171254.
Other sources
IBM Business Process Manager is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID CVE-2019-4669?
The vulnerability ID CVE-2019-4669 refers to a SQL injection vulnerability in IBM Business Process Manager and IBM Business Automation Workflow.
How can a remote attacker exploit CVE-2019-4669?
A remote attacker can exploit CVE-2019-4669 by sending specially-crafted SQL statements to the vulnerable system.
What is the severity of CVE-2019-4669?
The severity of CVE-2019-4669 is medium with a CVSS score of 6.3.
Which versions of IBM Business Process Manager are affected by CVE-2019-4669?
IBM Business Process Manager versions 8.5.7.0 through 8.5.7.0 2017.06, 8.6.0.0 through 8.6.0.0 CF2018.03, and IBM Business Automation Workflow versions 18.0.0.1 through 19.0.0.3 are affected by CVE-2019-4669.
How can I fix CVE-2019-4669?
To fix CVE-2019-4669, users should apply the necessary security patches provided by IBM.