CVE-2020-4768: XSS
IBM Case Manager 5.2 and 5.3 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188907.
Other sources
IBM Case Manager and IBM Business Automation Workflow are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4768?
The severity of CVE-2020-4768 is medium with a CVSS score of 5.4.
Which products are affected by CVE-2020-4768?
IBM Case Manager 5.2 and 5.3, IBM Business Automation Workflow 18.0, 19.0, and 20.0 are affected by CVE-2020-4768.
What is the vulnerability type of CVE-2020-4768?
CVE-2020-4768 is a cross-site scripting (XSS) vulnerability.
How can an attacker exploit CVE-2020-4768?
An attacker can exploit CVE-2020-4768 by embedding arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure.
Are there any references or additional information about CVE-2020-4768?
Yes, you can find more information about CVE-2020-4768 at the following URLs: [https://exchange.xforce.ibmcloud.com/vulnerabilities/188907](https://exchange.xforce.ibmcloud.com/vulnerabilities/188907) and [https://www.ibm.com/support/pages/node/6414377](https://www.ibm.com/support/pages/node/6414377).