VYPR
Medium severity5.4NVD Advisory· Published Dec 13, 2019· Updated Jun 17, 2026

CVE-2019-4426

CVE-2019-4426

Description

The Case Builder component shipped with 18.0.0.1 through 19.0.0.2 and IBM Case Manager 5.1.1 through 5.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162772.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

10
  • IBM/Business Automation Workflowcpe-rescue3 versions
    18.0.0.1+ 2 more
    • (no CPE)range: 18.0.0.1
    • cpe:2.3:a:ibm:business_automation_workflow:*:*:*:*:*:*:*:*range: >=19.0.0.0,<=19.0.0.3
    • cpe:2.3:a:ibm:business_automation_workflow:18.0.0.0:*:*:*:*:*:*:*
  • IBM/Case Managercpe-rescue6 versions
    5.1.1+ 5 more
    • (no CPE)range: 5.1.1
    • (no CPE)range: 5.1.1 - 5.3
    • cpe:2.3:a:ibm:case_manager:*:*:*:*:*:*:*:*range: >=5.3.0,<5.3.2
    • cpe:2.3:a:ibm:case_manager:5.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:case_manager:5.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:case_manager:5.2.1:*:*:*:*:*:*:*
  • IBM/Case Builderllm-fuzzy
    Range: 18.0.0.1 - 19.0.0.2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.

CVE-2019-4426 · Medium · VYPR