cbcvebase.
CVE-2019-4669
published 2020-02-27

CVE-2019-4669: IBM Business Process Manager 8.5.7.0 through 8.5.7.0 2017.06, 8.6.0.0 through 8.6.0.0 CF2018.03, and IBM Business Automation Workflow 18.0.0.1 through 19.0.0.3…

medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
IBM Business Process Manager 8.5.7.0 through 8.5.7.0 2017.06, 8.6.0.0 through 8.6.0.0 CF2018.03, and IBM Business Automation Workflow 18.0.0.1 through 19.0.0.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 171254.

Affected

7 ranges
VendorProductVersion rangeFixed in
ibmbusiness_automation_workflow
ibmbusiness_automation_workflow
ibmbusiness_automation_workflow18.0.0.1 – 19.0.0.3
ibmbusiness_process_manager
ibmbusiness_process_manager
ibmbusiness_process_manager
ibmbusiness_process_manager