Medium Severity

IBM Security Bulletin: Cross-site scripting vulnerability in IBM Business Automation Workflow and IBM Business Process Manager (BPM) (CVE-2019-4149)

Share this post:

A cross-site scripting vulnerability in IBM Business Automation Workflow and IBM BPM has been found.

CVE(s): CVE-2019-4149

Affected product(s) and affected version(s):

– IBM Business Automation Workflow V18.0.0.0 through V18.0.0.2

– IBM Business Process Manager V8.6.0.0 through V8.6.0.0 Cumulative Fix 2018.03

– IBM Business Process Manager V8.5.7.0 through V8.5.7.0 Cumulative Fix 2017.06

– IBM Business Process Manager V8.5.6.0 through V8.5.6.0 CF2

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10885104
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/158415

More stories

IBM Security Bulletin: IBM Security Key Lifecycle Manager stores password in clear text (CVE-2019-4566)

Sep 21, 2019 9:02 am EDT | Medium Severity

IBM Security Key Lifecycle Manager stores user credentials in plain in clear text which can be read by a local user. CVE(s): CVE-2019-4566 Affected product(s) and affected version(s): IBM Security Key Lifecycle Manager (SKLM) v3.0 – v3.0.0.2 on distributed platforms IBM Security Key Lifecycle Manager (SKLM) v3.0.1- v3.0.1.1 on distributed platforms Refer to the following ...read more


IBM Security Bulletin: Apache Commons Compress vulnerability affects IBM Spectrum Control (formerly Tivoli Storage Productivity Center) (CVE-2019-12402)

Sep 21, 2019 9:02 am EDT | Medium Severity

Apache Commons Compress is vulnerable to a denial of service which can affect IBM Spectrum Control (formerly IBM Tivoli Storage Productivity Center). CVE(s): CVE-2019-12402 Affected product(s) and affected version(s): Affected Product Affected Versions IBM Tivoli Storage Productivity Center 5.2.0 – 5.2.7.1 IBM Spectrum Control 5.2.8 – 5.2.17.3 IBM Spectrum Control 5.3.0 – 5.3.3 The versions ...read more


IBM Security Bulletin: Clickjacking vulnerability in WebSphere Application Server Liberty affects IBM Spectrum Control (formerly Tivoli Storage Productivity Center) (CVE-2019-4285)

Sep 21, 2019 9:01 am EDT | Medium Severity

There is a potential clickjacking vulnerability in IBM WebSphere Application Server Liberty Admin Center which affects IBM Spectrum Control (formerly Tivoli Storage Productivity Center). CVE(s): CVE-2019-4285 Affected product(s) and affected version(s): Affected Product Affected Versions IBM Spectrum Control 5.2.13 – 5.2.17.3 IBM Spectrum Control 5.3.0 – 5.3.3 The versions listed above apply to all licensed ...read more