cbcvebase.
CVE-2022-38390
published 2022-11-17

CVE-2022-38390: Multiple IBM Business Automation Workflow versions are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code…

medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
Multiple IBM Business Automation Workflow versions are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 233978.

Affected

10 ranges
VendorProductVersion rangeFixed in
ibmbusiness_automation_workflow
ibmbusiness_automation_workflow
ibmbusiness_automation_workflow
ibmbusiness_automation_workflow>= 18.0.0.0 < 18.0.0.218.0.0.2
ibmbusiness_automation_workflow18.0.0.0 – 18.0.0.2
ibmbusiness_automation_workflow>= 19.0.0.1 < 19.0.0.319.0.0.3
ibmbusiness_automation_workflow19.0.0.1 – 19.0.0.3
ibmbusiness_automation_workflow>= 20.0.0.1 < 20.0.0.220.0.0.2
ibmbusiness_automation_workflow>= 21.0.1 < 21.0.3.121.0.3.1
ibmbusiness_automation_workflow21.0.1 – 21.0.3.1