The optional component Process Federation Server that is shipped with IBM Business Process Manager and IBM Business Automation Workflow is vulnerable to a information disclosure and denial of service attack.
CVEID:CVE-2020-4794
**DESCRIPTION:**IBM Process Federation Server Component, IBM Business Automation Workflow and IBM Business Process Manager could allow an authenticated user to obtain sensitive information or cuase a denial of service due to iimproper authorization checking.
CVSS Base score: 5.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/189445 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L)
Affected Product(s) | Version(s) |
---|---|
IBM Cloud Pak for Automation | IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2 |
IBM Business Automation Workflow 20.0.2 | |
IBM Business Automation Workflow | V18.0, V19.0, V20.0 traditional |
V20.0 containers | |
IBM Business Process Manager | V8.6 |
The recommended solution is to apply the Interim Fix (iFix) or Cumulative Fix (CF) containing APAR JR62875 as soon as practical:
For Process Federation Server V18.0, V19.0, and V20.0:
ยท Upgrade to minimal cumulative fix levels as required by iFix and then apply iFix JR62875
--ORโ
ยท Apply cumulative fix Process Federation Server V20.0.0.2 or later
For Process Federation Server V8.6:
ยท Upgrade to minimal cumulative fix levels as required by iFix and then apply iFix JR62875
--ORโ
ยท Apply cumulative fix Process Federation Server V20.0.0.2 or later
For Process Federation Server in IBM Cloud Pak for Automation:
ยท Upgrade to version 20.0.3
None