Vulnerabilities (CVE)

Filtered by vendor Redhat Subscribe
Filtered by product Process Automation
Total 23 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-14862 3 Knockoutjs, Oracle, Redhat 5 Knockout, Business Intelligence, Goldengate and 2 more 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
CVE-2019-14841 1 Redhat 2 Decision Manager, Process Automation 2026-06-17 N/A 8.8 HIGH
A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attacker to gain admin privileges in the Business Central Console.
CVE-2019-14839 1 Redhat 3 Business-central, Descision Manager, Process Automation 2026-06-17 5.0 MEDIUM 7.5 HIGH
It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc.