Your review has been sent successfully

IBM Update

3385
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

5 September, 2019

● Medium

2019-400

All

Description:

IBM has released security update to address a vulnerability in the following products:

  • IBM Business Automation Workflow V18.0.0.0 - V18.0.0.2
  • IBM Business Process Manager V8.6.0.0 - V8.6.0.0
  • IBM Business Process Manager V8.5.7.0 - V8.5.7.0
  • IBM Business Process Manager V8.5.6.0 - V8.5.6.0 CF2

Threats:

Attacker could exploit this vulnerability by conducting cross-site scripting attack (XSS).

Best practice and Recommendations:

The CERT team encourages users to review IBM security advisory and apply the necessary updates:

https://www.ibm.com/support/pages/security-bulletin-cross-site-scripting-vulnerability-ibm-business-automation-workflow-and-ibm-business-process-manager-bpm-cve-2019-4149

Last updated at 28 October, 2019

Rate the content

rate-icon
up icon