Show filters
67 Total Results
Displaying 31-40 of 67
Sort by:
Attacker Value
Unknown
CVE-2020-26176
Disclosure Date: December 18, 2020 (last updated February 22, 2025)
An issue was discovered in tangro Business Workflow before 1.18.1. No (or broken) access control checks exist on the /api/document/<DocumentID>/attachments API endpoint. Knowing a document ID, an attacker can list all the attachments of a workitem, including their respective IDs. This allows the attacker to gather valid attachment IDs for workitems that do not belong to them.
0
Attacker Value
Unknown
CVE-2020-26172
Disclosure Date: December 18, 2020 (last updated February 22, 2025)
Every login in tangro Business Workflow before 1.18.1 generates the same JWT token, which allows an attacker to reuse the token when a session is active. The JWT token does not contain an expiration timestamp.
0
Attacker Value
Unknown
CVE-2020-26174
Disclosure Date: December 18, 2020 (last updated February 22, 2025)
tangro Business Workflow before 1.18.1 requests a list of allowed filetypes from the server and restricts uploads to the filetypes contained in this list. However, this restriction is enforced in the browser (client-side) and can be circumvented. This allows an attacker to upload any file as an attachment to a workitem.
0
Attacker Value
Unknown
CVE-2020-4794
Disclosure Date: December 18, 2020 (last updated February 22, 2025)
IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2, IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.6 could allow an authenticated user to obtain sensitive information or cuase a denial of service due to iimproper authorization checking. IBM X-Force ID: 189445.
0
Attacker Value
Unknown
CVE-2020-4900
Disclosure Date: November 26, 2020 (last updated February 22, 2025)
IBM Business Automation Workflow 19.0.0.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 190991.
0
Attacker Value
Unknown
CVE-2020-4672
Disclosure Date: November 13, 2020 (last updated February 22, 2025)
IBM Business Automation Workflow 20.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186285.
0
Attacker Value
Unknown
CVE-2020-4531
Disclosure Date: September 24, 2020 (last updated February 22, 2025)
IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 182715.
0
Attacker Value
Unknown
CVE-2020-4530
Disclosure Date: September 14, 2020 (last updated February 22, 2025)
IBM Business Automation Workflow C.D.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-ForceID: 182714.
0
Attacker Value
Unknown
CVE-2020-4516
Disclosure Date: September 04, 2020 (last updated February 22, 2025)
IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182371.
0
Attacker Value
Unknown
CVE-2020-4698
Disclosure Date: September 04, 2020 (last updated February 22, 2025)
IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186841.
0