Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Decision_manager
(Redhat)Repositories |
• https://github.com/FasterXML/jackson-databind
• https://github.com/kiegroup/jbpm-designer |
#Vulnerabilities | 20 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2020-03-05 | CVE-2019-14886 | A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_security_context. The encoding used for storing the passwords is Base64, not an encryption algorithm, and any recovery of these passwords could lead to user passwords being exposed. | Decision_manager, Process_automation_manager | 6.5 | ||
2022-10-17 | CVE-2019-14840 | A flaw was found in the RHDM, where sensitive HTML form fields like Password has auto-complete enabled which may lead to leak of credentials. | Decision_manager | 7.5 | ||
2022-10-17 | CVE-2019-14841 | A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attacker to gain admin privileges in the Business Central Console. | Decision_manager, Process_automation | 8.8 | ||
2020-01-02 | CVE-2019-14862 | There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it. | Knockout, Business_intelligence, Goldengate, Decision_manager, Process_automation | 6.1 | ||
2020-01-02 | CVE-2019-14863 | There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it. | Angular\.js, Decision_manager, Process_automation | N/A | ||
2018-07-26 | CVE-2017-7545 | It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE) attacks. | Decision_manager, Jboss_bpm_suite, Jbpm | 6.5 |