CVE-2020-4794Incorrect Authorization in IBM Automation Workstream Services

Severity
5.4MEDIUMNVD
EPSS
0.1%
top 67.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 21
Latest updateMay 24

Description

IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2, IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.6 could allow an authenticated user to obtain sensitive information or cuase a denial of service due to iimproper authorization checking. IBM X-Force ID: 189445.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:LExploitability: 2.8 | Impact: 2.5

Affected Packages6 packages

CVEListV5ibm/business_automation_workflow18.0, 19.0, 20.0+2
CVEListV5ibm/automation_workstream_services19.0.3, 20.0.1, 20.0.2+2
NVDibm/automation_workstream_services19.0.3, 20.0.1, 20.0.2+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jq8v-8c7p-26p2: IBM Automation Workstream Services 192022-05-24
CVEList
CVE-2020-4794: IBM Automation Workstream Services 192020-12-21
CVE-2020-4794 — Incorrect Authorization in IBM | cvebase