← Back

CVE-2022-22361

nvd nist
Published: May 31, 2022Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

IBM Business Automation Workflow traditional 21.0.1 through 21.0.3, 20.0.0.1 through 20.0.0.2, 19.0.0.1 through 19.0.0.3, 18.0.0.0 through 18.0.0.1, IBM Business Automation Workflow containers V21.0.1 - V21.0.3 20.0.0.1 through 20.0.0.2, IBM Business Process Manager 8.6.0.0 through 8.6.0.201803, and 8.5.0.0 through 8.5.0.201706 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

Affected (8)

2 products
Business Automation Workflow
Business Process Manager
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
From 19.0.0.1 to 19.0.0.3
From 21.0.1 to 21.0.3
Version 18.0.0.0
Version 18.0.0.1
Version 20.0.0.1
Version 20.0.0.2
Ibm
From 8.5.0.0 to 8.5.0.201706
From 8.6.0.0 to 8.6.0.201803

References (4)

Source: psirt@us.ibm.com
VDB EntryVendor Advisory
Source: psirt@us.ibm.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.