cbcvebase.
CVE-2019-4424
published 2019-08-20

CVE-2019-4424: IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, and 19.0.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when…

high8.2CVSS 3.1
AVNACLPRNUINSUCHINAL
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, and 19.0.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 162770.

Affected

13 ranges
VendorProductVersion rangeFixed in
ibmbusiness_automation_workflow
ibmbusiness_automation_workflow
ibmbusiness_automation_workflow
ibmbusiness_automation_workflow
ibmbusiness_automation_workflow
ibmbusiness_automation_workflow18.0.0.0 – 19.0.0.2
ibmbusiness_process_manager
ibmbusiness_process_manager
ibmbusiness_process_manager
ibmbusiness_process_manager
ibmbusiness_process_manager7.5.0.0 – 7.5.1.2
ibmbusiness_process_manager8.0.0.0 – 8.0.1.3
ibmbusiness_process_manager8.5.0.0 – 8.5.0.2