Medium Severity

Security Bulletin: SQL injection vulnerability in IBM Business Automation Workflow and IBM Business Process Manager (BPM) (CVE-2019-4479)

Share this post:

IBM Business Process Manager and IBM Business Automation Workflow is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.

Affected product(s) and affected version(s):

Affected Product(s) Version(s)
IBM Business Process Manager 8.5.7.0 – 8.5.7.0 2017.06
IBM Business Process Manager 8.6.0.0 – 8.6.0.0 CF2018.03
IBM Business Automation Workflow 18.0.0.1 – 19.0.0.3

Refer to the following reference URLs for remediation and additional vulnerability details:  
Source Bulletin: https://www.ibm.com/support/pages/node/3552261

More stories

Security Bulletin: Vulnerabilities in Apache Tomcat affects IBM Platform Symphony

Apr 6, 2020 8:00 pm EDT | Medium Severity

This interim fix provides instructions on upgrading Apache Tomcat to v8.5.53 in IBM Platform Symphony 7.1 Fix Pack 1 in order to address security vulnerabilities CVE-2020-1938, CVE-2020-1935 and CVE-2019-17569 in Apache Tomcat. ...read more


Security Bulletin: Security vulnerabilities in Dojo and jQuery might affect IBM Business Automation Workflow and IBM Business Process Manager (BPM)

Apr 6, 2020 8:00 pm EDT | Medium Severity

Security vulnerabilities have been reported for Dojo and jQuery version shipped with IBM Business Automation Workflow and IBM BPM. ...read more


Security Bulletin: IBM Security Guardium is affected by a kernel vulnerability

Apr 3, 2020 8:00 pm EDT | Medium Severity

IBM Security Guardium has fixed this vulnerability ...read more