Vulnerability Database

290,278

Total vulnerabilities in the database

CVE-2023-24957

IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3, 20.0.0.1, 20.0.0.2, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 246115.

  • Published: May 6, 2023
  • Updated: May 16, 2023
  • CVE: CVE-2023-24957
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 5.4
  • AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Software From Fixed in
ibm / business_automation_workflow 19.0.0.1 19.0.0.3.x
ibm / business_automation_workflow 18.0.0.0 18.0.0.0.x
ibm / business_automation_workflow 18.0.0.1 18.0.0.1.x
ibm / business_automation_workflow 18.0.0.2 18.0.0.2.x
ibm / business_automation_workflow 21.0.3-if011 21.0.3-if011.x
ibm / business_automation_workflow 21.0.3-if010 21.0.3-if010.x
ibm / business_automation_workflow 21.0.3-if009 21.0.3-if009.x
ibm / business_automation_workflow 21.0.3-if008 21.0.3-if008.x
ibm / business_automation_workflow 21.0.3-if007 21.0.3-if007.x
ibm / business_automation_workflow 21.0.3-if006 21.0.3-if006.x
ibm / business_automation_workflow 21.0.3-if005 21.0.3-if005.x
ibm / business_automation_workflow 21.0.3-if002 21.0.3-if002.x
ibm / business_automation_workflow 20.0.0.1 20.0.0.1.x
ibm / business_automation_workflow 20.0.0.2 20.0.0.2.x
ibm / business_automation_workflow 22.0.1 22.0.1.x
ibm / business_automation_workflow 21.0.1 21.0.3.1.x
ibm / business_automation_workflow 21.0.3-if012 21.0.3-if012.x
ibm / business_automation_workflow 21.0.3-if013 21.0.3-if013.x
ibm / business_automation_workflow 21.0.3-if014 21.0.3-if014.x
ibm / business_automation_workflow 22.0.2 22.0.2.x
ibm / business_automation_workflow 20.0.0.1 21.0.3
ibm / business_automation_workflow 22.0.1 22.0.2
ibm / business_automation_workflow 22.0.2-if001 22.0.2-if001.x
ibm / business_automation_workflow 21.0.3-if015 21.0.3-if015.x
ibm / business_automation_workflow 21.0.3-if016 21.0.3-if016.x
ibm / business_automation_workflow 21.0.3-if017 21.0.3-if017.x
ibm / business_automation_workflow 21.0.3 21.0.3.x