CVE-2020-4446

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/05/2020
Last modified:
08/05/2020

Description

IBM Business Process Manager 8.0, 8.5, and 8.6 and IBM Business Automation Workflow 18.0 and 19.0 could allow a remote attacker to bypass security restrictions, caused by the failure to perform insufficient authorization checks. IBM X-Force ID: 181126.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:business_automation_workflow:*:*:*:*:*:*:*:* 18.0.0.0 (including) 18.0.0.2 (including)
cpe:2.3:a:ibm:business_automation_workflow:*:*:*:*:*:*:*:* 19.0.0.1 (including) 19.0.0.3 (including)
cpe:2.3:a:ibm:business_process_manager:*:*:*:*:*:*:*:* 8.0.0.0 (including) 8.0.1.3 (including)
cpe:2.3:a:ibm:business_process_manager:*:*:*:*:*:*:*:* 8.5.0.0 (including) 8.5.7.0 (including)
cpe:2.3:a:ibm:business_process_manager:8.6.0.0:*:*:*:*:*:*:*