CVE-2018-1384
- EPSS 0.39%
- Veröffentlicht 30.03.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:43
IBM Business Process Manager 8.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a t...
CVE-2015-7454
- EPSS 0.16%
- Veröffentlicht 21.03.2016 14:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Business Space in IBM WebSphere Process Server 6.1.2.0 through 7.0.0.5 and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0.x through 8.5.0.2, 8.5.5.x through 8.5.5.0, and 8.5.6.x through 8.5.6.2 allows remote aut...
CVE-2015-7441
- EPSS 0.25%
- Veröffentlicht 01.01.2016 00:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Remote Artifact Loader (RAL) in IBM WebSphere Process Server 7 and Business Process Manager Advanced 7.5 through 7.5.1.2, 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.2, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.2 does not properly use SSL for its H...
CVE-2014-6176
- EPSS 0.36%
- Veröffentlicht 16.12.2014 23:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
IBM WebSphere Process Server 7.0, WebSphere Enterprise Service Bus 7.0, and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 disregard the SSL setting in the SCA module HTTP import binding and un...
- EPSS 0.27%
- Veröffentlicht 26.02.2009 16:17:19
- Zuletzt bearbeitet 23.04.2026 00:35:47
IBM WebSphere Process Server (WPS) 6.1.2 before 6.1.2.3 and 6.2 before 6.2.0.1 does not properly restrict configuration data during an export of the cluster configuration file from the administrative console, which allows remote authenticated users t...