IBM Business Automation Workflow是美国国际商业机器(IBM)公司的一套工作流程自动化解决方案。该产品主要用于工作流程管理、合规性管理,并具有工作流程可见性和可扩展等特点。 IBM Business Automation Workflow存在跨站脚本漏洞。攻击者利用该漏洞在Web UI中嵌入任意JavaScript代码,从而导致凭据泄露。以下版本受到影响:18.0.0.0版本、18.0.0.1版本、18.0.0.2版本、19.0.0.1版本、19.0.0.2版本、19.0.0
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | Business Automation Workflow | 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3, 20.0.0.1, 20.0.0.2, 21.0.2, 21.0.3, 22.0.1, 22.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-43877 | 5.1 MEDIUM | IBM UrbanCode Deploy (UCD) information disclosure |
| CVE-2022-22313 | 4.4 MEDIUM | IBM QRadar Data Synchronization App information disclosure |
No comments yet