Site icon API Security Blog

Security Bulletin: Cross-Site scripting vulnerability in ESAPI may affect IBM Business Automation Workflow – IBM X-Force ID: 273485

Summary IBM Business Automation Workflow is vulnerable to a Cross-Site scripting attack. Vulnerability Details ** IBM X-Force ID: 273485 DESCRIPTION: **Enterprise Security API for Java is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the Validator.isValidSafeHTML method. A remote attacker could exploit this vulnerability using a specially crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. CVSS Base score: 6.1 CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/273485 for the current score. CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) Affected Products and Versions Affected Product(s)| Version(s)| Status —|—|— IBM Business Automation Workflow containers| V23.0.2 – V23.0.2-IF001 V23.0.1 all fixes V22.0.2 all fixes V22.0.1 all fixes V21.0.3 – V21.0.3-IF028 V21.0.2 all fixes V20.0.0.2 all fixes V20.0.0.1 all fixes | affected IBM Business Automation Workflow traditional| V23.0.1 – V23.0.2 V22.0.1 – V22.0.2 V21.0.1 – V21.0.3.1 V20.0.0.1 – V20.0.0.2 V19.0.0.1 – V19.0.0.3| affected IBM Business Automation Workflow Enterprise Service Bus| V23.0.1 – V23.0.2 V22.0.2| affected For earlier and unsupported versions of the products, IBM recommends upgrading to a fixed, supported version of the product….Read More

Exit mobile version