Vulnerability Details CVE-2019-4149
                IBM Business Automation Workflow V18.0.0.0 through V18.0.0.2 and IBM Business Process Manager V8.6.0.0 through V8.6.0.0 Cumulative Fix 2018.03, V8.5.7.0 through V8.5.7.0 Cumulative Fix 2017.06, and V8.5.6.0 through V8.5.6.0 CF2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158415.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.003
                        
                    
                    
                        
                            EPSS Ranking 50.9%
                        
                    
                 
                
                    CVSS Severity
                    
                        
                            CVSS v3 Score 5.4
                        
                    
                    
                        
                            CVSS v2 Score 3.5
                        
                    
                 
                
                
                
                    
                
                
                    
                        Products affected by CVE-2019-4149
                        
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:ibm:business_automation_workflow:18.0.0.0
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:a:ibm:business_automation_workflow:18.0.0.1
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:a:ibm:business_automation_workflow:18.0.0.2
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:a:ibm:business_process_manager:8.5.6.0
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:a:ibm:business_process_manager:8.5.7.0
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:a:ibm:business_process_manager:8.6.0.0