CVE-2025-33142
- EPSS 0.05%
- Published 14.08.2025 15:41:59
- Last modified 18.08.2025 18:05:01
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections.
CVE-2024-28775
- EPSS 0.11%
- Published 01.05.2024 13:15:51
- Last modified 11.04.2025 14:09:38
IBM WebSphere Automation 1.7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tru...
CVE-2018-1848
- EPSS 0.24%
- Published 14.12.2018 16:29:00
- Last modified 21.11.2024 04:00:29
IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials...
CVE-2017-1756
- EPSS 0.05%
- Published 30.03.2018 16:29:00
- Last modified 21.11.2024 03:22:19
IBM Business Process Manager 8.6 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 135856.
CVE-2016-9693
- EPSS 0.18%
- Published 07.03.2017 17:59:00
- Last modified 20.04.2025 01:37:25
IBM Business Process Manager 7.5, 8.0, and 8.5 has a file download capability that is vulnerable to a set of attacks. Ultimately, an attacker can cause an unauthenticated victim to download a malicious payload. An existing file type restriction can b...
- EPSS 0.81%
- Published 28.06.2015 14:59:01
- Last modified 12.04.2025 10:46:40
Directory traversal vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 and WebSphere Lombardi Edition (WLE) 7.2 through 7.2.0.5 allows remote authenticate...
CVE-2015-0193
- EPSS 0.2%
- Published 30.05.2015 19:59:01
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5.0 and WebSphere Lombardi Edition (WLE) 7.2.x through 7.2.0.5 allows remote authenticated users to inj...
CVE-2015-0156
- EPSS 0.23%
- Published 25.05.2015 14:59:09
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.6.0 and WebSphere Lombardi Edition (WLE) 7.2.x through 7.2.0.5 allows remote authenticated users to inj...
- EPSS 1.54%
- Published 24.10.1999 04:00:00
- Last modified 03.04.2025 01:03:51
IBM WebSphere ikeyman tool uses weak encryption to store a password for a key database that is used for SSL connections.