Ibm Case Manager vulnerabilities

4 known vulnerabilities affecting ibm/case_manager.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2LOW1

Vulnerabilities

Page 1 of 1
CVE-2020-4768MEDIUMCVSS 5.4≥ 5.2.0, ≤ 5.3.3v5.2+1 more2021-02-11
CVE-2020-4768 [MEDIUM] CWE-79 CVE-2020-4768: IBM Case Manager 5.2 and 5.3 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerabl IBM Case Manager 5.2 and 5.3 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188907.
cvelistv5nvd
CVE-2019-4426MEDIUMCVSS 5.4≥ 5.3.0, < 5.3.2v5.1.1+3 more2019-12-13
CVE-2019-4426 [MEDIUM] CWE-79 CVE-2019-4426: The Case Builder component shipped with 18.0.0.1 through 19.0.0.2 and IBM Case Manager 5.1.1 through The Case Builder component shipped with 18.0.0.1 through 19.0.0.2 and IBM Case Manager 5.1.1 through 5.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID:
cvelistv5nvd
CVE-2018-1884HIGHCVSS 7.8v5.2.0.0v5.2.0.4+4 more2018-11-12
CVE-2018-1884 [HIGH] CWE-22 CVE-2018-1884: IBM Case Manager 5.2.0.0, 5.2.0.4, 5.2.1.0, 5.2.1.7, 5.3.0.0, and 5.3.3.0 is vulnerable to a "zip sl IBM Case Manager 5.2.0.0, 5.2.0.4, 5.2.1.0, 5.2.1.7, 5.3.0.0, and 5.3.3.0 is vulnerable to a "zip slip" vulnerability which could allow a remote attacker to execute code using directory traversal techniques. IBM X-Force ID: 151970.
cvelistv5nvd
CVE-2015-1979LOWCVSS 3.5v5.2.1v5.2.1.12015-07-20
CVE-2015-1979 [LOW] CWE-79 CVE-2015-1979: Multiple cross-site scripting (XSS) vulnerabilities in the Error dialog in IBM Case Manager 5.2.1 be Multiple cross-site scripting (XSS) vulnerabilities in the Error dialog in IBM Case Manager 5.2.1 before 5.2.1.2 allow remote authenticated users to inject arbitrary web script or HTML via crafted input to the (1) addressability or (2) comments component.
nvd