CVE-2018-2000
published 2019-04-08CVE-2018-2000: IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and…
PriorityP337high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
0.76%
51.3th percentile
IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 154890.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome_chrome | — | — | |
| ibm | business_automation_workflow | — | — |
| ibm | business_automation_workflow | — | — |
| ibm | business_process_manager | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j83f-fmmw-wc95: IBM Business Automation Workflow 18
ghsa_unreviewed·2022-05-13
CVE-2018-2000 [HIGH] CWE-352 GHSA-j83f-fmmw-wc95: IBM Business Automation Workflow 18
IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 154890.
Chrome
Stable Channel Update for Desktop: CVE-2023-1231
vendor_chrome·2023-03-07·CVSS 4.3
CVE-2023-1231 [MEDIUM] Stable Channel Update for Desktop: CVE-2023-1231
Stable Channel Update for Desktop
CVE-2023-1231: Inappropriate implementation in Autofill. Reported by Kirtikumar Anandrao Ramchandani via Yan Zhu of Brave on 2021-11-30 [$3000][ 813542 ] Low CVE-2023-2314: Insufficient data validation in DevTools
Reported by Rob Wu on 2018-02-19 [$2000][ 1346924 ] Low CVE-2023-1232: Insufficient policy enforcement in Resource Timing
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2019-13739
vendor_chrome·2019-12-10·CVSS 6.5
CVE-2019-13739 [MEDIUM] Stable Channel Update for Desktop: CVE-2019-13739
Stable Channel Update for Desktop
CVE-2019-13739: Incorrect security UI in Omnibox. Reported by xisigr of Tencent's Xuanwu Lab on 2018-03-22
[$2000][ 1005596 ] Medium CVE-2019-13740: Incorrect security UI in sharing
Reported by Khalil Zhani on 2019-09-19
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2019-5879
vendor_chrome·2019-09-10·CVSS 6.5
CVE-2019-5879 [MEDIUM] Stable Channel Update for Desktop: CVE-2019-5879
Stable Channel Update for Desktop
CVE-2019-5879: Extensions can read some local files. Reported by Jinseo Kim on 2019-07-20
[$2000][ 831725 ] Medium CVE-2019-5880: SameSite cookie bypass
Reported by Jun Kokatsu (@shhnjk) on 2018-04-11
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2019-5880
vendor_chrome·2019-09-10·CVSS 7.4
CVE-2019-5880 [MEDIUM] Stable Channel Update for Desktop: CVE-2019-5880
Stable Channel Update for Desktop
CVE-2019-5880: Insufficient policy enforcement in cookies. Reported by Isaac Dawson on 2018-01-18 [$2000][ 7 09946 ] Medium CVE-2019-5880: Insufficient policy enforcement in cookies
Reported by Gertjan Franken on 2017-04-10
Severity: medium
No detection rules found.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/107851https://exchange.xforce.ibmcloud.com/vulnerabilities/154890https://www.ibm.com/support/docview.wss?uid=ibm10870496http://www.securityfocus.com/bid/107851https://exchange.xforce.ibmcloud.com/vulnerabilities/154890https://www.ibm.com/support/docview.wss?uid=ibm10870496
2019-04-08
Published