Lucene search

K
cveIbmCVE-2020-4794
HistoryDec 21, 2020 - 6:15 p.m.

CVE-2020-4794

2020-12-2118:15:16
CWE-863
ibm
web.nvd.nist.gov
25
2
ibm
automation workstream services
business automation workflow
business process manager
cve-2020-4794
security vulnerability
authorization
nvd

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:N/A:P

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

24.8%

IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2, IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.6 could allow an authenticated user to obtain sensitive information or cuase a denial of service due to iimproper authorization checking. IBM X-Force ID: 189445.

Affected configurations

Nvd
Vulners
Node
ibmautomation_workstream_servicesMatch19.0.3
OR
ibmautomation_workstream_servicesMatch20.0.1
OR
ibmautomation_workstream_servicesMatch20.0.2
OR
ibmbusiness_process_managerMatch8.0.0.0express
OR
ibmbusiness_process_managerMatch8.0.0.0standard
OR
ibmbusiness_process_managerMatch8.0.1.0express
OR
ibmbusiness_process_managerMatch8.0.1.0standard
OR
ibmbusiness_process_managerMatch8.0.1.1express
OR
ibmbusiness_process_managerMatch8.0.1.1standard
OR
ibmbusiness_process_managerMatch8.0.1.2express
OR
ibmbusiness_process_managerMatch8.0.1.2standard
OR
ibmbusiness_process_managerMatch8.0.1.3express
OR
ibmbusiness_process_managerMatch8.0.1.3standard
OR
ibmbusiness_process_managerMatch8.5.0.0express
OR
ibmbusiness_process_managerMatch8.5.0.0standard
OR
ibmbusiness_process_managerMatch8.5.0.1express
OR
ibmbusiness_process_managerMatch8.5.0.1standard
OR
ibmbusiness_process_managerMatch8.5.0.2express
OR
ibmbusiness_process_managerMatch8.5.0.2standard
OR
ibmbusiness_process_managerMatch8.5.5.0express
OR
ibmbusiness_process_managerMatch8.5.5.0standard
OR
ibmbusiness_process_managerMatch8.5.6.0-express
OR
ibmbusiness_process_managerMatch8.5.6.0-standard
OR
ibmbusiness_process_managerMatch8.5.6.1express
OR
ibmbusiness_process_managerMatch8.5.6.1standard
OR
ibmbusiness_process_managerMatch8.5.6.2express
OR
ibmbusiness_process_managerMatch8.5.6.2standard
OR
ibmbusiness_process_managerMatch8.5.7.0express
OR
ibmbusiness_process_managerMatch8.5.7.0standard
OR
ibmbusiness_process_managerMatch8.5.7.0cf201606express
OR
ibmbusiness_process_managerMatch8.5.7.0cf201606standard
OR
ibmbusiness_process_managerMatch8.5.7.0cf201609express
OR
ibmbusiness_process_managerMatch8.5.7.0cf201609standard
OR
ibmbusiness_process_managerMatch8.5.7.0cf201612express
OR
ibmbusiness_process_managerMatch8.5.7.0cf201612standard
OR
ibmbusiness_process_managerMatch8.5.7.0cf201703express
OR
ibmbusiness_process_managerMatch8.5.7.0cf201703standard
OR
ibmbusiness_process_managerMatch8.5.7.0cf201706express
OR
ibmbusiness_process_managerMatch8.5.7.0cf201706standard
OR
ibmbusiness_process_managerMatch8.6express
OR
ibmbusiness_process_managerMatch8.6standard
Node
ibmbusiness_automation_workflowMatch18.0.0.0-
OR
ibmbusiness_automation_workflowMatch18.0.0.1-
OR
ibmbusiness_automation_workflowMatch18.0.0.2-
OR
ibmbusiness_automation_workflowMatch19.0.0.0-
OR
ibmbusiness_automation_workflowMatch19.0.0.1-
OR
ibmbusiness_automation_workflowMatch19.0.0.2-
OR
ibmbusiness_automation_workflowMatch19.0.0.3-
OR
ibmbusiness_automation_workflowMatch20.0.0.0docker
OR
ibmbusiness_automation_workflowMatch20.0.0.1-
OR
ibmbusiness_automation_workflowMatch20.0.2.0-
VendorProductVersionCPE
ibmautomation_workstream_services19.0.3cpe:2.3:a:ibm:automation_workstream_services:19.0.3:*:*:*:*:*:*:*
ibmautomation_workstream_services20.0.1cpe:2.3:a:ibm:automation_workstream_services:20.0.1:*:*:*:*:*:*:*
ibmautomation_workstream_services20.0.2cpe:2.3:a:ibm:automation_workstream_services:20.0.2:*:*:*:*:*:*:*
ibmbusiness_process_manager8.0.0.0cpe:2.3:a:ibm:business_process_manager:8.0.0.0:*:*:*:express:*:*:*
ibmbusiness_process_manager8.0.0.0cpe:2.3:a:ibm:business_process_manager:8.0.0.0:*:*:*:standard:*:*:*
ibmbusiness_process_manager8.0.1.0cpe:2.3:a:ibm:business_process_manager:8.0.1.0:*:*:*:express:*:*:*
ibmbusiness_process_manager8.0.1.0cpe:2.3:a:ibm:business_process_manager:8.0.1.0:*:*:*:standard:*:*:*
ibmbusiness_process_manager8.0.1.1cpe:2.3:a:ibm:business_process_manager:8.0.1.1:*:*:*:express:*:*:*
ibmbusiness_process_manager8.0.1.1cpe:2.3:a:ibm:business_process_manager:8.0.1.1:*:*:*:standard:*:*:*
ibmbusiness_process_manager8.0.1.2cpe:2.3:a:ibm:business_process_manager:8.0.1.2:*:*:*:express:*:*:*
Rows per page:
1-10 of 511

CNA Affected

[
  {
    "product": "Automation Workstream Services",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "19.0.3"
      },
      {
        "status": "affected",
        "version": "20.0.1"
      },
      {
        "status": "affected",
        "version": "20.0.2"
      }
    ]
  },
  {
    "product": "Business Process Manager",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "8.6"
      }
    ]
  },
  {
    "product": "Business Automation Workflow",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "19.0"
      },
      {
        "status": "affected",
        "version": "20.0"
      },
      {
        "status": "affected",
        "version": "18.0"
      }
    ]
  }
]

Social References

More

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:N/A:P

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

24.8%

Related for CVE-2020-4794