First published: Thu May 28 2020(Updated: )
IBM Business Automation Workflow 18 and 19, and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a vitcim to a phishing site. IBM X-Force ID: 181989
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Business Automation Workflow | <=V19.0V18.0 | |
IBM Business Process Manager | <=V8.6V8.5V8.0 | |
IBM Business Automation Workflow | =18.0.0.0 | |
IBM Business Automation Workflow | =19.0.0.0 | |
IBM Business Process Manager | =8.0.0.0 | |
IBM Business Process Manager | =8.5.0.0 | |
IBM Business Process Manager | =8.6.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-4490.
The severity level of CVE-2020-4490 is medium with a severity value of 6.1.
The vulnerability CVE-2020-4490 allows a remote attacker to bypass security restrictions and redirect a victim to a phishing site.
Versions 19.0 and 18.0 of IBM Business Automation Workflow are affected by CVE-2020-4490.
Versions 8.6, 8.5, and 8.0 of IBM Business Process Manager are affected by CVE-2020-4490.