CVE-2020-4698: XSS
IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186841.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2020-4698.
Which software versions are affected by this vulnerability?
IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are affected by this vulnerability.
What is the severity level of CVE-2020-4698?
The severity level of CVE-2020-4698 is medium, with a severity value of 5.4.
What is the impact of this vulnerability?
This vulnerability allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credential theft or other malicious activities.
Where can I find more information about this vulnerability?
More information about the vulnerability can be found at the following references: [link1](https://exchange.xforce.ibmcloud.com/vulnerabilities/186841) and [link2](https://www.ibm.com/support/pages/node/6326825).