cbcvebase.

Ibm Business Process Manager vulnerabilities

89 known vulnerabilities affecting ibm/business_process_manager.

Total CVEs
89
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH6MEDIUM69LOW13

Vulnerabilities

Page 1 of 5
CVE-2018-1674P3HIGHCVSS 8.8≥ 8.5.0.0, ≤ 8.5.0.2v8.5.5.0+21 more2018-09-20
CVE-2018-1674 [HIGH] CWE-89 CVE-2018-1674: IBM Business Process Manager 8.5 through 8.6 and 18.0.0.0 through 18.0.0.1 are vulnerable to SQL inj IBM Business Process Manager 8.5 through 8.6 and 18.0.0.0 through 18.0.0.1 are vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 145109.
nvd
CVE-2015-1961P3CRITICALCVSS 9.0v7.5.0.0v7.5.0.1+11 more2015-07-13
CVE-2015-1961 [CRITICAL] CWE-284 CVE-2015-1961: The REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5 The REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0 allows remote authenticated users to bypass intended access restrictions and execute arbitrary JavaScript code on the server via an unspecified API call.
nvd
CVE-2019-4424P3HIGHCVSS 8.2≥ 7.5.0.0, ≤ 7.5.1.2≥ 8.0.0.0, ≤ 8.0.1.3+5 more2019-08-20
CVE-2019-4424 [HIGH] CWE-611 CVE-2019-4424: IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, and 19.0.0.2 is vulnerable IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, and 19.0.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 162770.
nvd
CVE-2017-1527P3HIGHCVSS 8.1v7.5.0.0v7.5.0.1+16 more2017-09-26
CVE-2017-1527 [HIGH] CWE-611 CVE-2017-1527: IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to a XML External Entity Injection (XXE IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 130156.
nvd
CVE-2017-1539P3HIGHCVSS 8.8v7.5.0.0v7.5.0.1+16 more2017-09-26
CVE-2017-1539 [HIGH] CVE-2017-1539: IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to privilege escalation by not properly IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to privilege escalation by not properly distinguishing internal group memberships from user registry group memberships. By manipulating LDAP group membership an attack might gain privileged access. IBM X-Force ID: 130807.
nvd
CVE-2019-4669P3MEDIUMCVSS 6.3v8.5.7.0v8.6.0.0+2 more2020-02-27
CVE-2019-4669 [MEDIUM] CWE-89 CVE-2019-4669: IBM Business Process Manager 8.5.7.0 through 8.5.7.0 2017.06, 8.6.0.0 through 8.6.0.0 CF2018.03, and IBM Business Process Manager 8.5.7.0 through 8.5.7.0 2017.06, 8.6.0.0 through 8.6.0.0 CF2018.03, and IBM Business Automation Workflow 18.0.0.1 through 19.0.0.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
nvd
CVE-2017-1769P3HIGHCVSS 8.8v8.6.0.0v8.62018-01-24
CVE-2017-1769 [HIGH] CWE-352 CVE-2017-1769: IBM Business Process Manager 8.6 is vulnerable to cross-site request forgery which could allow an at IBM Business Process Manager 8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 136783.
nvd
CVE-2018-2000P3HIGHCVSS 8.8v8.6.0.02019-04-08
CVE-2018-2000 [HIGH] CWE-352 CVE-2018-2000: IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site request forgery w IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 154890.
nvd
CVE-2016-0349P3MEDIUMCVSS 6.5v8.5.6.0v8.5.7.02016-06-30
CVE-2016-0349 [MEDIUM] CWE-284 CVE-2016-0349: IBM Business Process Manager 8.5.6 through 8.5.6.2 and 8.5.7 before 8.5.7.CF201606 allows remote aut IBM Business Process Manager 8.5.6 through 8.5.6.2 and 8.5.7 before 8.5.7.CF201606 allows remote authenticated users to bypass intended access restrictions and update process-instance variables via a REST API call.
nvd
CVE-2017-1628P3MEDIUMCVSS 6.5v8.6.0.02017-11-27
CVE-2017-1628 [MEDIUM] CWE-863 CVE-2017-1628: IBM Business Process Manager 8.6.0.0 allows authenticated users to stop and resume the Event Manager IBM Business Process Manager 8.6.0.0 allows authenticated users to stop and resume the Event Manager by calling a REST API with incorrect authorization checks.
nvd
CVE-2015-7441P4MEDIUMCVSS 6.8v7.5.0.0v7.5.0.1+14 more2016-01-01
CVE-2015-7441 [MEDIUM] CWE-17 CVE-2015-7441: Remote Artifact Loader (RAL) in IBM WebSphere Process Server 7 and Business Process Manager Advanced Remote Artifact Loader (RAL) in IBM WebSphere Process Server 7 and Business Process Manager Advanced 7.5 through 7.5.1.2, 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.2, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.2 does not properly use SSL for its HTTPS connection, which allows remote authenticated users to obtain sensitive information or modify data
nvd
CVE-2021-38900P4MEDIUMCVSS 6.5v8.5.0.0v8.6.0.02021-12-21
CVE-2021-38900 [MEDIUM] CVE-2021-38900: IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 2 IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 could allow a privileged user to obtain highly sensitive information due to improper access controls. IBM X-Force ID: 209607.
nvd
CVE-2015-0110P4MEDIUMCVSS 6.5v7.5.0.0v7.5.0.1+11 more2017-09-15
CVE-2015-0110 [MEDIUM] CWE-284 CVE-2015-0110: IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka W IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka WLE) 7.2.x allow remote authenticated users to bypass intended access restrictions on internal service types via vectors involving the executeServiceByName URL.
nvd
CVE-2018-1997P4MEDIUMCVSS 6.5v8.5.5.0v8.5.6.0+2 more2019-04-08
CVE-2018-1997 [MEDIUM] CVE-2018-1997: IBM Business Automation Workflow and Business Process Manager 18.0.0.0, 18.0.0.1, and 18.0.0.2 are v IBM Business Automation Workflow and Business Process Manager 18.0.0.0, 18.0.0.1, and 18.0.0.2 are vulnerable to a denial of service attack. An authenticated attacker might send a specially crafted request that exhausts server-side memory. IBM X-Force ID: 154774.
nvd
CVE-2022-22361P4MEDIUMCVSS 6.5≥ 8.5.0.0, ≤ 8.5.0.201706≥ 8.6.0.0, ≤ 8.6.0.201803+4 more2022-05-31
CVE-2022-22361 [MEDIUM] CWE-352 CVE-2022-22361: IBM Business Automation Workflow traditional 21.0.1 through 21.0.3, 20.0.0.1 through 20.0.0.2, 19.0. IBM Business Automation Workflow traditional 21.0.1 through 21.0.3, 20.0.0.1 through 20.0.0.2, 19.0.0.1 through 19.0.0.3, 18.0.0.0 through 18.0.0.1, IBM Business Automation Workflow containers V21.0.1 - V21.0.3 20.0.0.1 through 20.0.0.2, IBM Business Process Manager 8.6.0.0 through 8.6.0.201803, and 8.5.0.0 through 8.5.0.201706 is vulnerable to cros
nvd
CVE-2021-29753P4MEDIUMCVSS 5.9v8.5.0.0v8.6.0.0+2 more2021-11-05
CVE-2021-29753 [MEDIUM] CWE-319 CVE-2021-29753: IBM Business Automation Workflow 18. 19, 20, 21, and IBM Business Process Manager 8.5 and d8.6 trans IBM Business Automation Workflow 18. 19, 20, 21, and IBM Business Process Manager 8.5 and d8.6 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
nvd
CVE-2014-4844P4MEDIUMCVSS 6.5v7.5.0.0v7.5.0.1+10 more2014-12-17
CVE-2014-4844 [MEDIUM] CWE-264 CVE-2014-4844: The import/export functionality in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x t The import/export functionality in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 allows remote authenticated users to bypass intended access restrictions via a project action for a (1) process application or (2) toolkit.
nvd
CVE-2018-1885P4MEDIUMCVSS 5.3≥ 7.5.0.0, ≤ 7.5.1.2≥ 8.0.0.0, ≤ 8.0.1.3+5 more2019-04-08
CVE-2018-1885 [MEDIUM] CWE-200 CVE-2018-1885: IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could allow an unauthenticated att IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could allow an unauthenticated attacker to obtain sensitve information using a specially cracted HTTP request. IBM X-Force ID: 152020.
nvd
CVE-2020-4490P4MEDIUMCVSS 6.1v8.0.0.0v8.5.0.0+1 more2020-05-29
CVE-2020-4490 [MEDIUM] CVE-2020-4490: IBM Business Automation Workflow 18 and 19, and IBM Business Process Manager 8.0, 8.5, and 8.6 could IBM Business Automation Workflow 18 and 19, and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a vitcim to a phishing site. IBM X-Force ID: 181989
nvd
CVE-2014-0908P4MEDIUMCVSS 6.0v7.5.0.0v7.5.0.1+9 more2014-04-10
CVE-2014-0908 [MEDIUM] CWE-264 CVE-2014-0908: The User Attribute implementation in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x The User Attribute implementation in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.2, and 8.5.x through 8.5.0.1 does not verify authorization for read or write access to attribute values, which allows remote authenticated users to obtain sensitive information, configure e-mail notifications, or modify task assignments v
nvd