CVE-2019-4424
20.08.2019, 20:15
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, and 19.0.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 162770.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | business_automation_workflow | 18.0.0.0 ≤ 𝑥 ≤ 19.0.0.2 |
ibm | business_process_manager | 7.5.0.0 ≤ 𝑥 ≤ 7.5.1.2 |
ibm | business_process_manager | 8.0.0.0 ≤ 𝑥 ≤ 8.0.1.3 |
ibm | business_process_manager | 8.5.0.0 ≤ 𝑥 ≤ 8.5.0.2 |
ibm | business_process_manager | 8.5.5.0 |
ibm | business_process_manager | 8.5.6.0 |
ibm | business_process_manager | 8.5.6.0:cf01 |
ibm | business_process_manager | 8.5.6.0:cf02 |
ibm | business_process_manager | 8.5.7.0 |
ibm | business_process_manager | 8.5.7.0:cf2016.06 |
ibm | business_process_manager | 8.5.7.0:cf2016.09 |
ibm | business_process_manager | 8.5.7.0:cf2016.12 |
ibm | business_process_manager | 8.5.7.0:cf2017.03 |
ibm | business_process_manager | 8.5.7.0:cf2017.06 |
ibm | business_process_manager | 8.6.0.0 |
ibm | business_process_manager | 8.6.0.0:cf2017.12 |
ibm | business_process_manager | 8.6.0.0:cf2018.03 |
𝑥
= Vulnerable software versions