Multiple IBM Products CVE-2019-4410 Cross Site Scripting Vulnerability
BID:108993
CVE-2019-4410 |Info
Multiple IBM Products CVE-2019-4410 Cross Site Scripting Vulnerability
| Bugtraq ID: | 108993 |
| Class: | Input Validation Error |
| CVE: |
CVE-2019-4410 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 28 2019 12:00AM |
| Updated: | Jun 28 2019 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
IBM Business Process Manager Advanced 8.5.7.0 CF 2017.06 IBM Business Process Manager Advanced 8.5.7.0 CF 2016.12 IBM Business Process Manager Advanced 8.5.7.0 IBM Business Process Manager 8.6.0.0 CF 2018.03 IBM Business Process Manager 8.6.0.0 CF 2017.12 IBM Business Process Manager 8.6.0.0 IBM Business Automation Workflow 19.0.0.1 IBM Business Automation Workflow 18.0.0.2 IBM Business Automation Workflow 18.0.0.1 IBM Business Automation Workflow 18.0.0.0 |
| Not Vulnerable: |
IBM Business Automation Workflow 19.0.0.2 |
Discussion
Multiple IBM Products CVE-2019-4410 Cross Site Scripting Vulnerability
Multiple IBM Products are prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
The following products are vulnerable:
IBM Business Automation Workflow 18.0.0.0 through 19.0.0.1
IBM Business Process Manager 8.6.0.0 through 8.6.0.0 Cumulative Fix 2018.03
IBM Business Process Manager V8.5.7.0 through 8.5.7.0 Cumulative Fix 2017.06
Multiple IBM Products are prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
The following products are vulnerable:
IBM Business Automation Workflow 18.0.0.0 through 19.0.0.1
IBM Business Process Manager 8.6.0.0 through 8.6.0.0 Cumulative Fix 2018.03
IBM Business Process Manager V8.5.7.0 through 8.5.7.0 Cumulative Fix 2017.06
References
Multiple IBM Products CVE-2019-4410 Cross Site Scripting Vulnerability
References:
References: