CVE-2022-42435: IBM Business Automation Workflow cross-site request forgery
IBM Business Automation Workflow 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, and 22.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 238054.
Other sources
IBM Business Automation Workflow is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-42435?
The severity of CVE-2022-42435 is high with a severity value of 8.8.
How does CVE-2022-42435 affect IBM Business Automation Workflow?
CVE-2022-42435 affects IBM Business Automation Workflow versions 18.0.0 to 22.0.1.
What is cross-site request forgery?
Cross-site request forgery (CSRF) is an attack that tricks the victim into submitting a malicious request.
How can an attacker exploit CVE-2022-42435?
An attacker can exploit CVE-2022-42435 by executing malicious and unauthorized actions through CSRF.
How can I fix CVE-2022-42435 in IBM Business Automation Workflow?
To fix CVE-2022-42435, update IBM Business Automation Workflow to a non-vulnerable version.