Ibm

Business Process Manager

88 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.6%
  • Published 26.09.2017 17:29:00
  • Last modified 20.04.2025 01:37:25

IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to privilege escalation by not properly distinguishing internal group memberships from user registry group memberships. By manipulating LDAP group membership an attack might gain privileged...

  • EPSS 0.27%
  • Published 26.09.2017 17:29:00
  • Last modified 20.04.2025 01:37:25

IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclos...

  • EPSS 0.27%
  • Published 26.09.2017 17:29:00
  • Last modified 20.04.2025 01:37:25

IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclos...

  • EPSS 0.54%
  • Published 26.09.2017 17:29:00
  • Last modified 20.04.2025 01:37:25

IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM...

  • EPSS 0.25%
  • Published 25.09.2017 16:29:00
  • Last modified 20.04.2025 01:37:25

IBM Business Process Manager 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a...

  • EPSS 0.04%
  • Published 25.09.2017 16:29:00
  • Last modified 20.04.2025 01:37:25

IBM Business Process Manager 7.5, 8.0, and 8.5 temporarily stores files in a temporary folder during offline installs which could be read by a local user within a short timespan. IBM X-Force ID: 126461.

  • EPSS 0.09%
  • Published 15.09.2017 20:29:00
  • Last modified 20.04.2025 01:37:25

IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka WLE) 7.2.x allow remote authenticated users to bypass intended access restrictions on internal service types via vectors involving the executeServiceBy...

  • EPSS 0.22%
  • Published 28.08.2017 15:29:00
  • Last modified 20.04.2025 01:37:25

Cross-site scripting (XSS) vulnerability in IBM Business Process Manager Standard 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5; IBM Business Process Manager Express 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5; and IBM Busines...

  • EPSS 0.27%
  • Published 08.06.2017 21:29:00
  • Last modified 20.04.2025 01:37:25

IBM Business Process Manager 8.0 and 8.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure w...

  • EPSS 0.1%
  • Published 22.05.2017 20:29:00
  • Last modified 20.04.2025 01:37:25

IBM Business Process Manager 8.0 and 8.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spo...