CVE-2020-4530: IBM Business Automation Workflow

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

IBM Business Automation Workflow C.D.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-ForceID: 182714.

Affected products

  • IBM Business Automation Workflow: before 20.0.0.2 (fixed in 20.0.0.2)
  • IBM Business Process Manager: from 8.0.0.0, before 8.0.1.0 (fixed in 8.0.1.0); from 8.5.0.0, before 8.5.7.0 (fixed in 8.5.7.0); version 8.6.0.0 only

Published 2020-09-15. Last modified 2026-06-17.