CVE-2022-38390: XSS
IBM Business Automation Workflow is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
Multiple IBM Business Automation Workflow versions are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 233978.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for IBM Business Automation Workflow?
The vulnerability ID for IBM Business Automation Workflow is CVE-2022-38390.
What is the severity of CVE-2022-38390?
The severity of CVE-2022-38390 is medium.
What is the impact of CVE-2022-38390?
CVE-2022-38390 allows users to embed arbitrary JavaScript code, potentially leading to credentials disclosure within a trusted session.
Which versions of IBM Business Automation Workflow are affected by CVE-2022-38390?
IBM Business Automation Workflow versions 18.0.0.0 to 18.0.0.2, 19.0.0.1 to 19.0.0.3, 20.0.0.1, 20.0.0.2, 21.0.1 to 21.0.3.1, and 22.0.1 are affected by CVE-2022-38390.
How can I fix CVE-2022-38390?
To fix CVE-2022-38390, it is recommended to apply the latest security updates provided by IBM.