CVE-2018-1848
14.12.2018, 16:29
IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150947.
Vendor | Product | Version |
---|---|---|
ibm | business_automation_workflow | 18.0.0.0 |
ibm | business_automation_workflow | 18.0.0.1 |
ibm | business_process_manager | 7.5.0.0 ≤ 𝑥 ≤ 7.5.1.2 |
ibm | business_process_manager | 8.0.0.0 ≤ 𝑥 ≤ 8.0.1.3 |
ibm | business_process_manager | 8.5.0.0 ≤ 𝑥 ≤ 8.5.0.2 |
ibm | business_process_manager | 8.5.5.0 |
ibm | business_process_manager | 8.5.6.0 |
ibm | business_process_manager | 8.5.6.0:cf1 |
ibm | business_process_manager | 8.5.6.0:cf2 |
ibm | business_process_manager | 8.5.7.0 |
ibm | business_process_manager | 8.5.7.0:cf201606 |
ibm | business_process_manager | 8.5.7.0:cf201609 |
ibm | business_process_manager | 8.5.7.0:cf201612 |
ibm | business_process_manager | 8.5.7.0:cf201703 |
ibm | business_process_manager | 8.5.7.0:cf201706 |
ibm | business_process_manager | 8.6.0.0 |
ibm | business_process_manager | 8.6.0.0:cf201712 |
ibm | business_process_manager | 8.6.0.0:cf201803 |
ibm | websphere | 7.2.0.0 ≤ 𝑥 ≤ 7.2.0.5 |
𝑥
= Vulnerable software versions
References