First published: Fri Dec 18 2020(Updated: )
IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2, IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.6 could allow an authenticated user to obtain sensitive information or cuase a denial of service due to iimproper authorization checking. IBM X-Force ID: 189445.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Automation Workstream Services | =19.0.3 | |
IBM Automation Workstream Services | =20.0.1 | |
IBM Automation Workstream Services | =20.0.2 | |
IBM Business Process Manager | =8.0.0.0 | |
IBM Business Process Manager | =8.0.0.0 | |
IBM Business Process Manager | =8.0.1.0 | |
IBM Business Process Manager | =8.0.1.0 | |
IBM Business Process Manager | =8.0.1.1 | |
IBM Business Process Manager | =8.0.1.1 | |
IBM Business Process Manager | =8.0.1.2 | |
IBM Business Process Manager | =8.0.1.2 | |
IBM Business Process Manager | =8.0.1.3 | |
IBM Business Process Manager | =8.0.1.3 | |
IBM Business Process Manager | =8.5.0.0 | |
IBM Business Process Manager | =8.5.0.0 | |
IBM Business Process Manager | =8.5.0.1 | |
IBM Business Process Manager | =8.5.0.1 | |
IBM Business Process Manager | =8.5.0.2 | |
IBM Business Process Manager | =8.5.0.2 | |
IBM Business Process Manager | =8.5.5.0 | |
IBM Business Process Manager | =8.5.5.0 | |
IBM Business Process Manager | =8.5.6.0 | |
IBM Business Process Manager | =8.5.6.0 | |
IBM Business Process Manager | =8.5.6.1 | |
IBM Business Process Manager | =8.5.6.1 | |
IBM Business Process Manager | =8.5.6.2 | |
IBM Business Process Manager | =8.5.6.2 | |
IBM Business Process Manager | =8.5.7.0 | |
IBM Business Process Manager | =8.5.7.0 | |
IBM Business Process Manager | =8.5.7.0-cf201606 | |
IBM Business Process Manager | =8.5.7.0-cf201606 | |
IBM Business Process Manager | =8.5.7.0-cf201609 | |
IBM Business Process Manager | =8.5.7.0-cf201609 | |
IBM Business Process Manager | =8.5.7.0-cf201612 | |
IBM Business Process Manager | =8.5.7.0-cf201612 | |
IBM Business Process Manager | =8.5.7.0-cf201703 | |
IBM Business Process Manager | =8.5.7.0-cf201703 | |
IBM Business Process Manager | =8.5.7.0-cf201706 | |
IBM Business Process Manager | =8.5.7.0-cf201706 | |
IBM Business Process Manager | =8.6 | |
IBM Business Process Manager | =8.6 | |
IBM Business Automation Workflow | =18.0.0.0 | |
IBM Business Automation Workflow | =18.0.0.1 | |
IBM Business Automation Workflow | =18.0.0.2 | |
IBM Business Automation Workflow | =19.0.0.0 | |
IBM Business Automation Workflow | =19.0.0.1 | |
IBM Business Automation Workflow | =19.0.0.2 | |
IBM Business Automation Workflow | =19.0.0.3 | |
IBM Business Automation Workflow | =20.0.0.0 | |
IBM Business Automation Workflow | =20.0.0.1 | |
IBM Business Automation Workflow | =20.0.2.0 | |
<=IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2IBM Business Automation Workflow 20.0.2 | ||
<=V18.0, V19.0, V20.0 traditionalV20.0 containers | ||
<=V8.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4794 has a severity rating that indicates it could allow unauthorized access to sensitive information or cause denial of service.
To fix CVE-2020-4794, apply the patches released by IBM for affected versions of their software.
CVE-2020-4794 affects IBM Automation Workstream Services, IBM Business Automation Workflow, and IBM Business Process Manager.
Yes, CVE-2020-4794 can potentially lead to data breaches due to improper authorization checking.
Yes, mitigating CVE-2020-4794 is important for maintaining the security and privacy of sensitive information in your organization.