CVE-2017-1539
- EPSS 0.6%
- Veröffentlicht 26.09.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to privilege escalation by not properly distinguishing internal group memberships from user registry group memberships. By manipulating LDAP group membership an attack might gain privileged...
CVE-2017-1531
- EPSS 0.27%
- Veröffentlicht 26.09.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclos...
CVE-2017-1530
- EPSS 0.27%
- Veröffentlicht 26.09.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclos...
CVE-2017-1527
- EPSS 0.54%
- Veröffentlicht 26.09.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM...
CVE-2017-1424
- EPSS 0.25%
- Veröffentlicht 25.09.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM Business Process Manager 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a...
CVE-2017-1346
- EPSS 0.04%
- Veröffentlicht 25.09.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM Business Process Manager 7.5, 8.0, and 8.5 temporarily stores files in a temporary folder during offline installs which could be read by a local user within a short timespan. IBM X-Force ID: 126461.
CVE-2015-0110
- EPSS 0.09%
- Veröffentlicht 15.09.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka WLE) 7.2.x allow remote authenticated users to bypass intended access restrictions on internal service types via vectors involving the executeServiceBy...
CVE-2015-0101
- EPSS 0.22%
- Veröffentlicht 28.08.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager Standard 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5; IBM Business Process Manager Express 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5; and IBM Busines...
CVE-2017-1140
- EPSS 0.27%
- Veröffentlicht 08.06.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM Business Process Manager 8.0 and 8.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure w...
CVE-2017-1159
- EPSS 0.1%
- Veröffentlicht 22.05.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM Business Process Manager 8.0 and 8.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spo...