
CVE-2020-4900
https://notcve.org/view.php?id=CVE-2020-4900
30 Nov 2020 — IBM Business Automation Workflow 19.0.0.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 190991. IBM Business Automation Workflow versión 19.0.0.3, almacena información potencialmente confidencial en archivos de registro que un usuario local podría leer. IBM X-Force ID: 190991 • https://exchange.xforce.ibmcloud.com/vulnerabilities/190991 • CWE-532: Insertion of Sensitive Information into Log File •

CVE-2020-4672
https://notcve.org/view.php?id=CVE-2020-4672
16 Nov 2020 — IBM Business Automation Workflow 20.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186285. IBM Business Automation Workflow versión 20.0.0.1, es vulnerable a un ataque de tipo cross-site scripting. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrario en la interfaz de usuari... • https://exchange.xforce.ibmcloud.com/vulnerabilities/186285 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2020-4531
https://notcve.org/view.php?id=CVE-2020-4531
25 Sep 2020 — IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 182715. IBM Business Automation Workflow versiones 18.0, 19.0 y 20.0 e IBM Business Process Manager versiones 8.0, 8.5 y 8.6, podrían permitir a un atacante remoto obtener información confide... • https://exchange.xforce.ibmcloud.com/vulnerabilities/182715 • CWE-252: Unchecked Return Value •

CVE-2020-4530
https://notcve.org/view.php?id=CVE-2020-4530
15 Sep 2020 — IBM Business Automation Workflow C.D.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-ForceID: 182714. IBM Business Automation Workflow CD0 e IBM Business Process Manager versiones 8.0, 8.5 y 8.6, son vulnerables a ataques de tipo cross-site scripting. Esta vulne... • https://exchange.xforce.ibmcloud.com/vulnerabilities/182714 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2020-4698
https://notcve.org/view.php?id=CVE-2020-4698
08 Sep 2020 — IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186841. IBM Business Process Manager versiones 8.5, 8.6 e IBM Business Automation Workflow versiones 18.0, 19.0 y 20.0, son vulnerables a ataques de tipo cross... • https://exchange.xforce.ibmcloud.com/vulnerabilities/186841 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2020-4516
https://notcve.org/view.php?id=CVE-2020-4516
08 Sep 2020 — IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182371. IBM Business Process Manager versiones 8.5, 8.6 e IBM Business Automation Workflow versiones 18.0, 19.0 y 20.0, son vulnerables a ataques de tipo cross-site s... • https://exchange.xforce.ibmcloud.com/vulnerabilities/182371 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2020-4557
https://notcve.org/view.php?id=CVE-2020-4557
29 Jun 2020 — IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 183611. IBM Business Automation Workflow versiones 18.0, 19.0 y 20.0 e IBM Business Process Manager versiones 8.5 y 8.6, son vulnerables a un ataque de tipo cross-... • https://exchange.xforce.ibmcloud.com/vulnerabilities/183611 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2020-4532
https://notcve.org/view.php?id=CVE-2020-4532
17 Jun 2020 — IBM Business Automation Workflow and IBM Business Process Manager (IBM Business Process Manager Express 8.5.5, 8.5.6, 8.5.7, and 8.6) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 182716. IBM Business Automation Workflow e IBM Business Process Manager (IBM Business Process Manager Express versiones 8.5.5, 8.5.6, 8.5.7 y 8.6), podrían permit... • https://exchange.xforce.ibmcloud.com/vulnerabilities/182716 • CWE-209: Generation of Error Message Containing Sensitive Information •

CVE-2020-4490
https://notcve.org/view.php?id=CVE-2020-4490
29 May 2020 — IBM Business Automation Workflow 18 and 19, and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a vitcim to a phishing site. IBM X-Force ID: 181989 IBM Business Automation Workflow versiones 18 y 19, e IBM Business Process Manager versiones 8.0, 8.5 y 8.6, podrían permitir a un atacante remoto omitir restricciones de seguridad, causadas por un fallo de ... • https://exchange.xforce.ibmcloud.com/vulnerabilities/181989 •

CVE-2020-4446
https://notcve.org/view.php?id=CVE-2020-4446
06 May 2020 — IBM Business Process Manager 8.0, 8.5, and 8.6 and IBM Business Automation Workflow 18.0 and 19.0 could allow a remote attacker to bypass security restrictions, caused by the failure to perform insufficient authorization checks. IBM X-Force ID: 181126. IBM Business Process Manager versiones 8.0, 8.5 y 8.6 e IBM Business Automation Workflow versiones 18.0 y 19.0, podrían permitir a un atacante remoto omitir las restricciones de seguridad, causadas mediante el fallo al realizar comprobaciones de autorización ... • https://exchange.xforce.ibmcloud.com/vulnerabilities/181126 • CWE-863: Incorrect Authorization •