First published: Thu Oct 14 2021(Updated: )
IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 206581.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Business Automation Workflow | =18.0.0.0 | |
IBM Business Automation Workflow | =18.0.0.1 | |
IBM Business Automation Workflow | =18.0.0.2 | |
IBM Business Automation Workflow | =19.0.0.0 | |
IBM Business Automation Workflow | =19.0.0.1 | |
IBM Business Automation Workflow | =19.0.0.2 | |
IBM Business Automation Workflow | =19.0.0.3 | |
IBM Business Automation Workflow | =20.0.0.0 | |
IBM Business Automation Workflow | =20.0.0.1 | |
IBM Business Automation Workflow | =20.0.0.2 | |
IBM Business Automation Workflow | =21.0.2 | |
<=V21.0V20.0V19.0V18.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure.
The severity of CVE-2021-29878 is medium with a CVSS score of 5.4.
This vulnerability can be exploited by embedding malicious JavaScript code in the Web UI of IBM Business Automation Workflow to execute arbitrary actions within a trusted session.
Yes, IBM has released patches to address this vulnerability. It is recommended to update to the latest version of IBM Business Automation Workflow to mitigate the risk.
You can find more information about CVE-2021-29878 on the IBM X-Force Exchange website and the IBM Support Page.