6.4
CVSSv2

CVE-2019-4424

Published: 20/08/2019 Updated: 02/12/2022
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 8.2 | Impact Score: 4.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, and 19.0.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 162770.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ibm business process manager 8.5.5.0

ibm business process manager 8.5.7.0

ibm business process manager

ibm business process manager 8.5.6.0

ibm business process manager 8.6.0.0

ibm business automation workflow