IBM Support

JR62271: SECURITY APAR - CVE-2020-4446 - INSUFFICIENT AUTHORIZATION WHEN SHOWING PERFORMANCE METRICS

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • CVEID: CVE-2020-4446
    Description: IBM Business Process Manager and IBM Business
    Automation Workflow could allow a remote attacker to bypass
    security restrictions, caused by the failure to perform
    insufficient authorization checks.
    CVSS Base Score: 4.3
    CVSS Temporal Score:
    https://exchange.xforce.ibmcloud.com/vulnerabilities/181126 for
    more information
    CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
    Affected Platforms:
    
    
    PRODUCTS AFFECTED
    IBM Business Process Manager (BPM) Advanced
    IBM BPM Standard
    IBM BPM Express
    IBM Business Automation Workflow
    

Local fix

Problem summary

  • No additional information is available.
    

Problem conclusion

  • A fix that enforces expected authorization checks is planned for
     inclusion in the latest fix packs of IBM BPM 8.0.1.3, IBM BPM
    8.5 and 8.6, the latest two fix packs of Business Automation
    Workflow, and all future releases.
    
    On V19.0.0.3, the JR62271 is replaced by JR62678 iFix in Fix
    Central.
    

Temporary fix

Comments

APAR Information

  • APAR number

    JR62271

  • Reported component name

    BUS AUTO WORKFL

  • Reported component ID

    5737H4100

  • Reported release

    I00

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2020-04-24

  • Closed date

    2020-05-05

  • Last modified date

    2022-09-08

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    BUS AUTO WORKFL

  • Fixed component ID

    5737H4100

Applicable component levels

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS8JB4","label":"IBM Business Automation Workflow"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"18.0.0.0","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
08 September 2022