VendorsIBMbusiness_automation_workflow22.0.1
Vulnerabilities

IBM Business Automation Workflow 22.0.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2022-42435
IBM Business Automation Workflow cross-site request forgery
Published 2023-01-03 · Modified
8.8EPSS 0.003
CVE-2022-43864
IBM Business Automation Workflow information disclosure
Published 2023-01-25 · Modified
7.5EPSS 0.020
CVE-2024-38321
IBM Business Automation Workflow information disclosure
Published 2024-08-03 · Analyzed
6.5EPSS 0.004
CVE-2022-41735
IBM Business Process Manager cross-site scripting
Published 2022-12-07 · Modified
6.1EPSS 0.004
CVE-2023-50947
IBM Business Automation Workflow cross-site scripting
Published 2024-02-04 · Modified
5.4EPSS 0.004
CVE-2022-38390
Multiple IBM Business Automation Workflow versions are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 233978.
Published 2022-11-17 · Modified
5.4EPSS 0.004
CVE-2023-24957
IBM Business Automation Workflow cross-site scripting
Published 2023-05-06 · Modified
5.4EPSS 0.004
CVE-2024-43188
IBM Business Automation Workflow improper input validation
Published 2024-09-18 · Analyzed
4.9EPSS 0.003
CVE-2022-35279
"IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3, 20.0.0.1, 20.0.0.2, 21.0.2, 21.0.3, and 22.0.1 could disclose sensitive version information to authenticated users which could be used in further attacks against the system. IBM X-Force ID: 230537."
Published 2022-11-03 · Modified
4.3EPSS 0.003