First published: Tue May 05 2020(Updated: )
IBM Business Process Manager 8.0, 8.5, and 8.6 and IBM Business Automation Workflow 18.0 and 19.0 could allow a remote attacker to bypass security restrictions, caused by the failure to perform insufficient authorization checks. IBM X-Force ID: 181126.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Business Automation Workflow | <=V19.0V18.0 | |
IBM Business Process Manager | <=V8.6V8.5V8.0 | |
IBM Business Automation Workflow | >=18.0.0.0<=18.0.0.2 | |
IBM Business Automation Workflow | >=19.0.0.1<=19.0.0.3 | |
IBM Business Process Manager | >=8.0.0.0<=8.0.1.3 | |
IBM Business Process Manager | >=8.5.0.0<=8.5.7.0 | |
IBM Business Process Manager | =8.6.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for IBM Business Process Manager and IBM Business Automation Workflow vulnerability is CVE-2020-4446.
The severity level of CVE-2020-4446 is medium, with a CVSS score of 4.3.
A remote attacker can exploit CVE-2020-4446 by bypassing security restrictions due to insufficient authorization checks.
IBM Business Process Manager versions 8.0, 8.5, 8.6, and IBM Business Automation Workflow versions 18.0 and 19.0 are affected by CVE-2020-4446.
Yes, you can find references for CVE-2020-4446 from IBM X-Force ID 181126 and the IBM support page.