Thursday, April 4, 2019

IBM Security Bulletin: Cross-site request forgery vulnerability in IBM Business Automation Workflow (CVE-2018-2000)

Apr 4, 2019 10:01 am EDT

Categorized: Medium Severity

Share this post:

A Cross-site request forgery vulnerability has been found in IBM Business Automation Workflow.

CVE(s): CVE-2018-2000

Affected product(s) and affected version(s):

– IBM Business Automation Workflow V18.0.0.0 through V18.0.0.1

– IBM Business Process Manager V8.6.0.0 Cumulative Fix 2017.12 through V8.6.0.0 Cumulative Fix 2018.03

Note: A fix for IBM Business Automation Workflow V18.0.0.2 is available even though IBM Business Automation Workflow V18.0.0.2 is not vulnerable to this security issue. The intention of this interim fix is to prevent the following unnecessary warning message in IBM Installation Manager, which you see when you upgrade IBM Business Automation Workflow:

“One or more fixes will be uninstalled when IBM(R) Business Automation Workflow is updated to V18.0.0.2. The update does not address issues that were resolved previously by the maintenance packages. The problems might return if fixes for the the following issues are not reapplied or have new fixes applied to prevent the problems from returning.
– JR60539 in the package IBM(R) Business Automation Workflow …”

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10870496
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/154890



from IBM Product Security Incident Response Team https://ift.tt/2TXUZbr

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.