CVE-2018-1674: IBM Business Automation Workflow
High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.
IBM Business Process Manager 8.5 through 8.6 and 18.0.0.0 through 18.0.0.1 are vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 145109.
Affected products
- IBM Business Automation Workflow: version 18.0.0.0 only; version 18.0.0.1 only
- IBM Business Process Manager: from 8.5.0.0, up to and including 8.5.0.2; version 8.5.5.0 only; version 8.5.6.0 only; version 8.5.7.0 only; version 8.6.0.0 only
Published 2018-09-20. Last modified 2026-06-17.