VendorsIBMbusiness_automation_workflowall versions
Vulnerabilities

IBM Business Automation Workflow

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

54CVEs
CVE-2024-54179
IBM Business Automation Workflow cross-site scripting
Published 2025-03-03 · Analyzed
5.4EPSS 0.003
CVE-2018-1885
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could allow an unauthenticated attacker to obtain sensitve information using a specially cracted HTTP request. IBM X-Force ID: 152020.
Published 2019-04-08 · Modified
5.3EPSS 0.018
CVE-2020-4531
IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 182715.
Published 2020-09-25 · Modified
5.3EPSS 0.014
CVE-2020-4532
IBM Business Automation Workflow and IBM Business Process Manager (IBM Business Process Manager Express 8.5.5, 8.5.6, 8.5.7, and 8.6) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 182716.
Published 2020-06-17 · Modified
5.3EPSS 0.013
CVE-2021-39046
IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 and IBM Business Process Manager 8.5 and 8.6 stores user credentials in plain clear text which can be read by a lprivileged user. IBM X-Force ID: 214346.
Published 2022-03-18 · Modified
4.9EPSS 0.009
CVE-2024-43188
IBM Business Automation Workflow improper input validation
Published 2024-09-18 · Analyzed
4.9EPSS 0.003
CVE-2018-1999
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could reveal sensitive version information about the server from error pages that could aid an attacker in further attacks against the system. IBM X-Force ID: 154889.
Published 2019-04-08 · Modified
4.3EPSS 0.010
CVE-2020-4446
IBM Business Process Manager 8.0, 8.5, and 8.6 and IBM Business Automation Workflow 18.0 and 19.0 could allow a remote attacker to bypass security restrictions, caused by the failure to perform insufficient authorization checks. IBM X-Force ID: 181126.
Published 2020-05-06 · Modified
4.3EPSS 0.009
CVE-2019-4045
IBM Business Automation Workflow and IBM Business Process Manager 18.0.0.0, 18.0.0.1, and 18.0.0.2 provide embedded document management features. Because of a missing restriction in an API, a client might spoof the last modified by value of a document. IBM X-Force ID: 156241.
Published 2019-04-08 · Modified
4.3EPSS 0.009
CVE-2021-29751
IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 could allow an authenticated user to obtain sensitive information about another user under nondefault configurations. IBM X-Force ID: 201779.
Published 2021-06-28 · Modified
4.3EPSS 0.009
CVE-2022-35279
"IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3, 20.0.0.1, 20.0.0.2, 21.0.2, 21.0.3, and 22.0.1 could disclose sensitive version information to authenticated users which could be used in further attacks against the system. IBM X-Force ID: 230537."
Published 2022-11-03 · Modified
4.3EPSS 0.003
CVE-2025-1495
IBM Business Automation Workflow missing authentication
Published 2025-05-03 · Analyzed
4.3EPSS 0.002
CVE-2026-1248
IBM Business Automation Workflow information leak
Published 2026-05-27 · Analyzed
4.3EPSS 0.002
CVE-2026-12730
Improper Validation of Certificate with Host Mismatch in IBM Business Automation Workflow containers
Published 2026-08-05 · Analyzed
3.8EPSS 0.002
← Prev2 / 2