First published: Thu Nov 26 2020(Updated: )
IBM Business Automation Workflow 19.0.0.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 190991.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Business Automation Workflow | =19.0.0.3 | |
<=V19.0.0.3 with interim fix JR62240 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-4900 is medium with a severity value of 5.5.
IBM Business Automation Workflow version 19.0.0.3 and V19.0.0.3 with interim fix JR62240 are affected by CVE-2020-4900.
CVE-2020-4900 allows a local user to read potentially sensitive information from log files stored by IBM Business Automation Workflow.
Apply the necessary updates or interim fix provided by IBM to address CVE-2020-4900 in IBM Business Automation Workflow.
You can find more information about CVE-2020-4900 on the IBM X-Force ID page (190991) and the IBM support page.