Known vulnerabilities in IBM Business Process Manager 8.6.0.CF201803
Vendor:
IBM Corporation
Software:
IBM Business Process Manager
Version:
8.6.0.CF201803
Software CPE:
cpe:2.3:a:ibm_corporation:ibm_business_process_manager:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
6
Public exploits:
1
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
8.6
8.5
8.6.0.0 CF2018.03
8.5.7 CF2017.06
19.0.0.3
19.0.0.2
19.0.0.1
20.0.0.2
20.0.0.1
21.0.2
21.0.3.1
-
21.0.3
18.0.0.1
18.0.0.0
8.6.0.CF201803
8.6.0.CF201712
8.5.7.CF201706
8.5.7.CF201703
8.5.7.CF201612
8.5.7.CF201609
8.5.7.CF201606
7.0.0.5
7.0.0.4
7.0.0.3
7.0.0.2
7.0.0.1
7.0.0.0
8.4
8.3
8.2
8.1
8.6.0
8.5.7.0
8.5.0.2
8.5.6.1
8.5.6.2
8.5.6.0
8.0.1.3
8.5.5.0
8.0.1.1
8.0.1.2
8.5.0.0
8.5.0.1
7.5.1.2
7.5.0.0
7.5.0.1
8.0.0.0
8.0.1.0
7.5.1.1
7.5.1.0
8.5.7
8.5.6
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU61799 - Out-of-bounds write CVE-2020-36518 |
CWE-787 | Medium | - | 01.04.2022 |
SB2022040113 SB2022040114 SB2022040115 and 147 more |
||
| #VU58816 - Improper Control of Generation of Code ('Code Injection') CVE-2021-44228 |
CWE-94 | Critical | - | 10.12.2021 |
SB2021121003 SB2021121101 SB2021121201 and 338 more |
||
| #VU14916 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2018-1674 |
CWE-89 | Medium | - | 27.09.2018 |
SB2018092704 |
||
| #VU11268 - Deserialization of Untrusted Data CVE-2018-7489 |
CWE-502 | High | - | 26.03.2018 |
SB2018021604 SB2018041910 SB2018050306 and 27 more |
||
| #VU10610 - Deserialization of Untrusted Data CVE-2018-5968 |
CWE-502 | High | - | 16.02.2018 |
SB2018021604 SB2018021605 SB2018051725 and 13 more |
||
| #VU10257 - Deserialization of Untrusted Data CVE-2017-17485 |
CWE-502 | High | - | 26.01.2018 |
SB2017121218 SB2018021605 SB2018051725 and 23 more |