First published: Fri May 27 2022(Updated: )
IBM Business Automation Workflow is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Business Automation Workflow | >=19.0.0.1<=19.0.0.3 | |
IBM Business Automation Workflow | >=21.0.1<=21.0.3 | |
IBM Business Automation Workflow | =18.0.0.0 | |
IBM Business Automation Workflow | =18.0.0.1 | |
IBM Business Automation Workflow | =20.0.0.1 | |
IBM Business Automation Workflow | =20.0.0.2 | |
IBM Business Process Manager | >=8.5.0.0<=8.5.0.201706 | |
IBM Business Process Manager | >=8.6.0.0<=8.6.0.201803 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-22361 is medium.
IBM Business Automation Workflow versions 18.0.0.0 through 18.0.0.1, 19.0.0.1 through 19.0.0.3, 20.0.0.1 through 20.0.0.2, and 21.0.1 through 21.0.3 are affected by CVE-2022-22361.
Apply the necessary patches and updates provided by IBM to fix CVE-2022-22361.
You can find more information about CVE-2022-22361 on the IBM X-Force Exchange website and the IBM Support page.
The CWE ID of CVE-2022-22361 is 352.