CVE-2018-1885: IBM Business Automation Workflow

Medium severity, CVSS 5.3. EPSS: 1.8% chance of exploitation in the next 30 days.

IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could allow an unauthenticated attacker to obtain sensitve information using a specially cracted HTTP request. IBM X-Force ID: 152020.

Affected products

  • IBM Business Automation Workflow: version 18.0.0.0 only; version 18.0.0.1 only; version 18.0.0.2 only
  • IBM Business Process Manager: from 7.5.0.0, up to and including 7.5.1.2; from 8.0.0.0, up to and including 8.0.1.3; from 8.5.0.0, up to and including 8.5.0.2; version 8.5.5.0 only; version 8.5.6.0 only; version 8.5.7.0 only; …
  • IBM Business Process Manager Enterprise Service Bus: version 8.6 only
  • IBM WebSphere Enterprise Service Bus: from 7.0.0.0, up to and including 7.5.1.2

Published 2019-04-08. Last modified 2026-06-17.