Ibm Business Process Manager vulnerabilities
89 known vulnerabilities affecting ibm/business_process_manager.
Total CVEs
89
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH6MEDIUM69LOW13
Vulnerabilities
Page 2 of 5
CVE-2015-7454P4MEDIUMCVSS 4.3v7.5.0.0v7.5.0.1+15 more2016-03-21
CVE-2015-7454 [MEDIUM] CWE-264 CVE-2015-7454: Business Space in IBM WebSphere Process Server 6.1.2.0 through 7.0.0.5 and Business Process Manager
Business Space in IBM WebSphere Process Server 6.1.2.0 through 7.0.0.5 and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0.x through 8.5.0.2, 8.5.5.x through 8.5.5.0, and 8.5.6.x through 8.5.6.2 allows remote authenticated users to bypass intended access restrictions and create an arbitrary page or space via unspec
nvd
CVE-2019-4425P4MEDIUMCVSS 5.7≥ 8.0.0.0, ≤ 8.0.1.3≥ 8.5.0.0, ≤ 8.5.0.2+4 more2019-08-20
CVE-2019-4425 [MEDIUM] CVE-2019-4425: IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could allow a user to obtain highl
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could allow a user to obtain highly sensitive information from another user by inserting links that would be clicked on by unsuspecting users. IBM X-Force ID: 162771.
nvd
CVE-2021-29834P4MEDIUMCVSS 5.4v8.5.0.0v8.6.0.0+2 more2021-09-29
CVE-2021-29834 [MEDIUM] CWE-79 CVE-2021-29834: IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3,20.0.0.1
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3,20.0.0.1, 20.0.0.2, and 21.0.2 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lea
nvd
CVE-2015-1884P4MEDIUMCVSS 4.0v7.5.0.0v7.5.0.1+11 more2015-06-28
CVE-2015-1884 [MEDIUM] CWE-22 CVE-2015-1884: Directory traversal vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x
Directory traversal vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 and WebSphere Lombardi Edition (WLE) 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via a crafted internationalization-file URL.
nvd
CVE-2015-8524P4MEDIUMCVSS 6.1v8.5.0.0v8.5.0.1+4 more2016-02-29
CVE-2015-8524 [MEDIUM] CWE-79 CVE-2015-8524: Cross-site scripting (XSS) vulnerability in Process Portal in IBM Business Process Manager 8.5.0.x t
Cross-site scripting (XSS) vulnerability in Process Portal in IBM Business Process Manager 8.5.0.x through 8.5.0.2, 8.5.5.x through 8.5.5.0, and 8.5.6.x through 8.5.6.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2018-1848P4MEDIUMCVSS 6.1≥ 7.5.0.0, ≤ 7.5.1.2≥ 8.0.0.0, ≤ 8.0.1.3+5 more2018-12-14
CVE-2018-1848 [MEDIUM] CWE-79 CVE-2018-1848: IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site scripting. This v
IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150947.
nvd
CVE-2015-0101P4MEDIUMCVSS 6.1v7.5v7.5.0.1+11 more2017-08-28
CVE-2015-0101 [MEDIUM] CWE-79 CVE-2015-0101: Cross-site scripting (XSS) vulnerability in IBM Business Process Manager Standard 7.5.x before 7.5,
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager Standard 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5; IBM Business Process Manager Express 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5; and IBM Business Process Manager Advanced 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5.
nvd
CVE-2022-41735P4MEDIUMCVSS 6.1≥ 21.0.1, < 21.0.3.1≥ 20.0.0.1, < 20.0.0.2+1 more2022-12-07
CVE-2022-41735 [MEDIUM] CWE-79 CVE-2022-41735: IBM Business Process Manager 21.0.1 through 21.0.3.1, 20.0.0.1 through 20.0.0.2 19.0.0.1 through 19.
IBM Business Process Manager 21.0.1 through 21.0.3.1, 20.0.0.1 through 20.0.0.2 19.0.0.1 through 19.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force I
nvd
CVE-2020-4531P4MEDIUMCVSS 5.3v8.0.0.0v8.5.0.0+4 more2020-09-25
CVE-2020-4531 [MEDIUM] CWE-252 CVE-2020-4531: IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.0, 8.5, and
IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 182715.
nvd
CVE-2020-4532P4MEDIUMCVSS 5.3≥ 8.5.5.0, < 8.5.7.0v8.6.0.02020-06-17
CVE-2020-4532 [MEDIUM] CWE-209 CVE-2020-4532: IBM Business Automation Workflow and IBM Business Process Manager (IBM Business Process Manager Expr
IBM Business Automation Workflow and IBM Business Process Manager (IBM Business Process Manager Express 8.5.5, 8.5.6, 8.5.7, and 8.6) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 182
nvd
CVE-2020-4794P4MEDIUMCVSS 5.4v8.0.0.0v8.0.1.0+12 more2020-12-21
CVE-2020-4794 [MEDIUM] CWE-863 CVE-2020-4794: IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2, IBM Business Automation Workflow 18.0, 19
IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2, IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.6 could allow an authenticated user to obtain sensitive information or cuase a denial of service due to iimproper authorization checking. IBM X-Force ID: 189445.
nvd
CVE-2020-4516P4MEDIUMCVSS 5.4v8.5.0.0v8.5.0.1+9 more2020-09-08
CVE-2020-4516 [MEDIUM] CWE-79 CVE-2020-4516: IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are
IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182371.
nvd
CVE-2021-38893P4MEDIUMCVSS 5.4v8.5.0.0v8.5.5.0+2 more2021-12-21
CVE-2021-38893 [MEDIUM] CWE-79 CVE-2021-38893: IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 2
IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-F
nvd
CVE-2020-4698P4MEDIUMCVSS 5.4v8.5.0.0v8.5.0.1+9 more2020-09-08
CVE-2020-4698 [MEDIUM] CWE-79 CVE-2020-4698: IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are
IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 18
nvd
CVE-2021-38883P4MEDIUMCVSS 5.4v8.5.0.0v8.5.0.1+7 more2021-12-17
CVE-2021-38883 [MEDIUM] CWE-79 CVE-2021-38883: IBM Business Automation Workflow 18.0, 19.0, 20,0 and 21.0 and IBM Business Process Manager 8.5 and
IBM Business Automation Workflow 18.0, 19.0, 20,0 and 21.0 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID:
nvd
CVE-2019-4410P4MEDIUMCVSS 5.4v8.6.0.0v8.5.7.02019-07-01
CVE-2019-4410 [MEDIUM] CWE-79 CVE-2019-4410: IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, and 19.0.0.1 is vulnerable to cross-s
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, and 19.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162657.
nvd
CVE-2019-4204P4MEDIUMCVSS 5.4v8.5.7.0v8.6.0.02019-05-10
CVE-2019-4204 [MEDIUM] CWE-79 CVE-2019-4204: IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, and 19.0.0.1 is vulnerable to cross-s
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, and 19.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159125.
nvd
CVE-2019-4149P4MEDIUMCVSS 5.4v8.5.6.0v8.5.7.0+4 more2019-09-05
CVE-2019-4149 [MEDIUM] CWE-79 CVE-2019-4149: IBM Business Automation Workflow V18.0.0.0 through V18.0.0.2 and IBM Business Process Manager V8.6.0
IBM Business Automation Workflow V18.0.0.0 through V18.0.0.2 and IBM Business Process Manager V8.6.0.0 through V8.6.0.0 Cumulative Fix 2018.03, V8.5.7.0 through V8.5.7.0 Cumulative Fix 2017.06, and V8.5.6.0 through V8.5.6.0 CF2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus a
nvd
CVE-2020-4530P4MEDIUMCVSS 5.4≥ 8.0.0.0, < 8.0.1.0≥ 8.5.0.0, < 8.5.7.0+4 more2020-09-15
CVE-2020-4530 [MEDIUM] CWE-79 CVE-2020-4530: IBM Business Automation Workflow C.D.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 are vulner
IBM Business Automation Workflow C.D.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-ForceID: 182714.
nvd
CVE-2020-4557P4MEDIUMCVSS 5.4v8.5.0.0v8.6.0.0+2 more2020-06-29
CVE-2020-4557 [MEDIUM] CWE-79 CVE-2020-4557: IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 a
IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 18361
nvd