First published: Fri Dec 30 2022(Updated: )
IBM Business Automation Workflow 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, and 22.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 238054.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Business Automation Workflow | =18.0.0 | |
IBM Business Automation Workflow | =18.0.1 | |
IBM Business Automation Workflow | =18.0.2 | |
IBM Business Automation Workflow | =19.0.1 | |
IBM Business Automation Workflow | =19.0.2 | |
IBM Business Automation Workflow | =19.0.3 | |
IBM Business Automation Workflow | =20.0.1 | |
IBM Business Automation Workflow | =20.0.2 | |
IBM Business Automation Workflow | =20.0.3 | |
IBM Business Automation Workflow | =21.0.1 | |
IBM Business Automation Workflow | =21.0.1-if001 | |
IBM Business Automation Workflow | =21.0.1-if002 | |
IBM Business Automation Workflow | =21.0.1-if003 | |
IBM Business Automation Workflow | =21.0.1-if004 | |
IBM Business Automation Workflow | =21.0.1-if005 | |
IBM Business Automation Workflow | =21.0.1-if006 | |
IBM Business Automation Workflow | =21.0.1-if007 | |
IBM Business Automation Workflow | =21.0.2 | |
IBM Business Automation Workflow | =21.0.2-if001 | |
IBM Business Automation Workflow | =21.0.2-if002 | |
IBM Business Automation Workflow | =21.0.2-if003 | |
IBM Business Automation Workflow | =21.0.2-if004 | |
IBM Business Automation Workflow | =21.0.2-if005 | |
IBM Business Automation Workflow | =21.0.2-if006 | |
IBM Business Automation Workflow | =21.0.2-if007 | |
IBM Business Automation Workflow | =21.0.2-if008 | |
IBM Business Automation Workflow | =21.0.2-if009 | |
IBM Business Automation Workflow | =21.0.2-if010 | |
IBM Business Automation Workflow | =21.0.2-if011 | |
IBM Business Automation Workflow | =21.0.2-if012 | |
IBM Business Automation Workflow | =21.0.3 | |
IBM Business Automation Workflow | =21.0.3-if001 | |
IBM Business Automation Workflow | =21.0.3-if002 | |
IBM Business Automation Workflow | =21.0.3-if003 | |
IBM Business Automation Workflow | =21.0.3-if004 | |
IBM Business Automation Workflow | =21.0.3-if005 | |
IBM Business Automation Workflow | =21.0.3-if006 | |
IBM Business Automation Workflow | =21.0.3-if007 | |
IBM Business Automation Workflow | =21.0.3-if008 | |
IBM Business Automation Workflow | =21.0.3-if009 | |
IBM Business Automation Workflow | =21.0.3-if010 | |
IBM Business Automation Workflow | =21.0.3-if011 | |
IBM Business Automation Workflow | =21.0.3-if012 | |
IBM Business Automation Workflow | =21.0.3-if013 | |
IBM Business Automation Workflow | =21.0.3-if014 | |
IBM Business Automation Workflow | =21.0.3-if015 | |
IBM Business Automation Workflow | =22.0.1 | |
IBM Business Automation Workflow | =22.0.1-if001 | |
IBM Business Automation Workflow | =22.0.1-if002 | |
IBM Business Automation Workflow | =22.0.1-if003 | |
IBM Business Automation Workflow | =22.0.1-if004 | |
IBM Business Automation Workflow | =22.0.1-if005 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-42435 is high with a severity value of 8.8.
CVE-2022-42435 affects IBM Business Automation Workflow versions 18.0.0 to 22.0.1.
Cross-site request forgery (CSRF) is an attack that tricks the victim into submitting a malicious request.
An attacker can exploit CVE-2022-42435 by executing malicious and unauthorized actions through CSRF.
To fix CVE-2022-42435, update IBM Business Automation Workflow to a non-vulnerable version.