Known vulnerabilities in IBM Business Process Manager 8.5.7.CF201706
Vendor:
IBM Corporation
Software:
IBM Business Process Manager
Version:
8.5.7.CF201706
Software CPE:
cpe:2.3:a:ibm_corporation:ibm_business_process_manager:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
5
Public exploits:
1
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
8.6
8.5
8.6.0.0 CF2018.03
8.5.7 CF2017.06
19.0.0.3
19.0.0.2
19.0.0.1
20.0.0.2
20.0.0.1
21.0.2
21.0.3.1
-
21.0.3
18.0.0.1
18.0.0.0
8.6.0.CF201803
8.6.0.CF201712
8.5.7.CF201706
8.5.7.CF201703
8.5.7.CF201612
8.5.7.CF201609
8.5.7.CF201606
7.0.0.5
7.0.0.4
7.0.0.3
7.0.0.2
7.0.0.1
7.0.0.0
8.4
8.3
8.2
8.1
8.6.0
8.5.7.0
8.5.0.2
8.5.6.1
8.5.6.2
8.5.6.0
8.0.1.3
8.5.5.0
8.0.1.1
8.0.1.2
8.5.0.0
8.5.0.1
7.5.1.2
7.5.0.0
7.5.0.1
8.0.0.0
8.0.1.0
7.5.1.1
7.5.1.0
8.5.7
8.5.6
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU58816 - Improper Control of Generation of Code ('Code Injection') CVE-2021-44228 |
CWE-94 | Critical | - | 10.12.2021 |
SB2021121003 SB2021121101 SB2021121201 and 338 more |
||
| #VU14916 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2018-1674 |
CWE-89 | Medium | - | 27.09.2018 |
SB2018092704 |
||
| #VU11268 - Deserialization of Untrusted Data CVE-2018-7489 |
CWE-502 | High | - | 26.03.2018 |
SB2018021604 SB2018041910 SB2018050306 and 27 more |
||
| #VU10610 - Deserialization of Untrusted Data CVE-2018-5968 |
CWE-502 | High | - | 16.02.2018 |
SB2018021604 SB2018021605 SB2018051725 and 13 more |
||
| #VU10257 - Deserialization of Untrusted Data CVE-2017-17485 |
CWE-502 | High | - | 26.01.2018 |
SB2017121218 SB2018021605 SB2018051725 and 23 more |