CVE-2021-38893: XSS
IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 209512.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-38893.
Which products are affected by this vulnerability?
IBM Business Process Manager 8.5, 8.6, and IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 are affected.
What is the severity level of CVE-2021-38893?
The severity level of CVE-2021-38893 is medium.
What is the impact of this vulnerability?
This vulnerability allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credential theft or unauthorized actions.
How can I fix this vulnerability?
Update to a version that is not affected by this vulnerability when available, or apply any patches or mitigations provided by IBM.