CVE-2020-4530: XSS
IBM Business Automation Workflow and IBM Business Process Manager are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Business Automation Workflow C.D.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-ForceID: 182714.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-4530.
What is the severity of CVE-2020-4530?
The severity of CVE-2020-4530 is medium with a CVSS score of 5.4.
Which products are affected by CVE-2020-4530?
IBM Business Automation Workflow C.D.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 are affected by CVE-2020-4530.
What is the impact of CVE-2020-4530?
The vulnerability allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure.
How can I fix CVE-2020-4530?
There is currently no fix available for CVE-2020-4530. IBM recommends applying security mitigations provided in the Security Bulletin.