CVE-2020-4794

MEDIUM WAF: Low
CVSS 5.4 Published: 2020-12-21
CWE-863

IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2, IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.6 could allow an authenticated user to obtain sensitive information or cuase a denial of service due to iimproper authorization checking. IBM X-Force ID: 189445.

WAF Coverage Analysis

Incorrect Authorization Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Affected Software

VendorProductVersion
ibmautomation_workstream_services19.0.3
ibmautomation_workstream_services20.0.1
ibmautomation_workstream_services20.0.2
ibmbusiness_process_manager8.0.0.0
ibmbusiness_process_manager8.0.0.0
ibmbusiness_process_manager8.0.1.0
ibmbusiness_process_manager8.0.1.0
ibmbusiness_process_manager8.0.1.1
ibmbusiness_process_manager8.0.1.1
ibmbusiness_process_manager8.0.1.2

References

Back to CVE Database