CVE-2020-4446: Medium severity IBM Business Automation Workflow vulnerability
IBM Business Process Manager 8.0, 8.5, and 8.6 and IBM Business Automation Workflow 18.0 and 19.0 could allow a remote attacker to bypass security restrictions, caused by the failure to perform insufficient authorization checks. IBM X-Force ID: 181126.
Other sources
IBM Business Process Manager and IBM Business Automation Workflow could allow a remote attacker to bypass security restrictions, caused by the failure to perform insufficient authorization checks.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for IBM Business Process Manager and IBM Business Automation Workflow vulnerability?
The vulnerability ID for IBM Business Process Manager and IBM Business Automation Workflow vulnerability is CVE-2020-4446.
What is the severity level of CVE-2020-4446?
The severity level of CVE-2020-4446 is medium, with a CVSS score of 4.3.
How can a remote attacker exploit CVE-2020-4446?
A remote attacker can exploit CVE-2020-4446 by bypassing security restrictions due to insufficient authorization checks.
Which versions of IBM Business Process Manager and IBM Business Automation Workflow are affected by CVE-2020-4446?
IBM Business Process Manager versions 8.0, 8.5, 8.6, and IBM Business Automation Workflow versions 18.0 and 19.0 are affected by CVE-2020-4446.
Are there any references available for CVE-2020-4446?
Yes, you can find references for CVE-2020-4446 from IBM X-Force ID 181126 and the IBM support page.