Lucene search

K
ibmIBME037B2EAC38A9A0040FEBA5E5622F2D399CFF1A1DE2CCDFF52879503F759FAAE
HistoryNov 30, 2020 - 5:20 p.m.

Security Bulletin: Information disclosure vulnerability may affect IBM Business Automation Workflow - CVE-2020-4900

2020-11-3017:20:18
www.ibm.com
12
ibm business automation workflow
information disclosure
vulnerability
cve-2020-4900
log files
security bulletin
interim fix
cumulative fix
apar jr62972

EPSS

0

Percentile

5.1%

Summary

IBM Business Process Manager and IBM Business Automation Workflow are vulnerable to an information disclosure attack.

Vulnerability Details

CVEID:CVE-2020-4900
**DESCRIPTION:**IBM Business Automation Workflow stores potentially sensitive information in log files that could be read by a local user.
CVSS Base score: 5.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/190991 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Business Automation Workflow V19.0.0.3 with interim fix JR62240

Remediation/Fixes

The recommended solution is to apply the Interim Fix (iFix) or Cumulative Fix (CF) containing APAR JR62972 as soon as practical:

For IBM Business Automation Workflow V19.0.0.3 with APAR JR62240 applied
ยท Apply iFix JR62972
--ORโ€“
ยท Apply cumulative fix Business Automation Workflow V20.0.0.2 or later

Workarounds and Mitigations

None

EPSS

0

Percentile

5.1%

Related for E037B2EAC38A9A0040FEBA5E5622F2D399CFF1A1DE2CCDFF52879503F759FAAE