Ibm · Ibm Business Process Manager · CVE-2020-4698
Name of the Vulnerable Software and Affected Versions:
IBM Business Process Manager versions 8.5 through 8.6
IBM Business Automation Workflow versions 18.0 through 20.0
Description:
The issue is related to stored cross-site scripting, allowing users to embed arbitrary JavaScript code in the Web UI, potentially altering the intended functionality and leading to credentials disclosure within a trusted session. This can be exploited by a remote attacker to perform cross-site scripting attacks.
Recommendations:
For IBM Business Process Manager versions 8.5 through 8.6, update to a version that includes the fix for this issue.
For IBM Business Automation Workflow versions 18.0 through 20.0, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the Web UI to minimize the risk of exploitation.