Apr 4, 2019 10:01 am EDT
Categorized: Medium Severity
Share this post:
A Cross-site request forgery vulnerability has been found in IBM Business Automation Workflow.
CVE(s): CVE-2018-2000
Affected product(s) and affected version(s):
– IBM Business Automation Workflow V18.0.0.0 through V18.0.0.1
– IBM Business Process Manager V8.6.0.0 Cumulative Fix 2017.12 through V8.6.0.0 Cumulative Fix 2018.03
Note: A fix for IBM Business Automation Workflow V18.0.0.2 is available even though IBM Business Automation Workflow V18.0.0.2 is not vulnerable to this security issue. The intention of this interim fix is to prevent the following unnecessary warning message in IBM Installation Manager, which you see when you upgrade IBM Business Automation Workflow:
“One or more fixes will be uninstalled when IBM(R) Business Automation Workflow is updated to V18.0.0.2. The update does not address issues that were resolved previously by the maintenance packages. The problems might return if fixes for the the following issues are not reapplied or have new fixes applied to prevent the problems from returning.
– JR60539 in the package IBM(R) Business Automation Workflow …”
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10870496
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/154890
from IBM Product Security Incident Response Team https://ift.tt/2TXUZbr
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.