Lucene search

K
ibmIBMF9C5347A7C48DB87FDC44D831629E28B7374E9503AF5FB5C3B6DA5F199E973D2
HistoryDec 18, 2020 - 7:04 a.m.

Security Bulletin: Information disclosure and Denial of Service vulnerability affect IBM Business Automation Workflow and IBM Business Process Manager (BPM) - CVE-2020-4794

2020-12-1807:04:17
www.ibm.com
15
ibm process federation server
ibm business automation workflow
business process manager
information disclosure
denial of service
vulnerability
cve-2020-4794
interim fix
cumulative fix
ibm cloud pak for automation
version 20.0.2
version 18.0
version 19.0
container
upgrade.

EPSS

0.001

Percentile

24.8%

Summary

The optional component Process Federation Server that is shipped with IBM Business Process Manager and IBM Business Automation Workflow is vulnerable to a information disclosure and denial of service attack.

Vulnerability Details

CVEID:CVE-2020-4794
**DESCRIPTION:**IBM Process Federation Server Component, IBM Business Automation Workflow and IBM Business Process Manager could allow an authenticated user to obtain sensitive information or cuase a denial of service due to iimproper authorization checking.
CVSS Base score: 5.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/189445 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Cloud Pak for Automation IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2
IBM Business Automation Workflow 20.0.2
IBM Business Automation Workflow V18.0, V19.0, V20.0 traditional
V20.0 containers
IBM Business Process Manager V8.6

Remediation/Fixes

The recommended solution is to apply the Interim Fix (iFix) or Cumulative Fix (CF) containing APAR JR62875 as soon as practical:

For Process Federation Server V18.0, V19.0, and V20.0:
ยท Upgrade to minimal cumulative fix levels as required by iFix and then apply iFix JR62875
--ORโ€“
ยท Apply cumulative fix Process Federation Server V20.0.0.2 or later

For Process Federation Server V8.6:
ยท Upgrade to minimal cumulative fix levels as required by iFix and then apply iFix JR62875
--ORโ€“
ยท Apply cumulative fix Process Federation Server V20.0.0.2 or later

For Process Federation Server in IBM Cloud Pak for Automation:
ยท Upgrade to version 20.0.3

Workarounds and Mitigations

None

EPSS

0.001

Percentile

24.8%

Related for F9C5347A7C48DB87FDC44D831629E28B7374E9503AF5FB5C3B6DA5F199E973D2