Page 16 of 91 results (0.001 seconds)

CVSS: 6.5EPSS: 0%CPEs: 12EXPL: 0

The import/export functionality in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 allows remote authenticated users to bypass intended access restrictions via a project action for a (1) process application or (2) toolkit. La funcionalidad import/export en IBM Business Process Manager (BPM) 7.5.x hasta 7.5.1.2, 8.0.x hasta 8.0.1.3, y 8.5.x hasta 8.5.5 permite a usuarios remotos autenticados evadir las restricciones de acceso a través de una acción de proyecto para (1) una aplicación de proyecto o (2) una caja de herramientas. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR51286 http://www.ibm.com/support/docview.wss?uid=swg21690554 https://exchange.xforce.ibmcloud.com/vulnerabilities/95724 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 4.0EPSS: 0%CPEs: 8EXPL: 0

Directory traversal vulnerability in an export function in the Process Center in IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3 and 8.5.x through 8.5.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL. Vulnerabilidad de salto de directorio en una función de exportación en el centro de procesos en IBM Business Process Manager (BPM) 8.0.x hasta 8.0.1.3 y 8.5.x hasta 8.5.5 permite a usuarios remotos autenticados leer ficheros arbitrarios a través de un .. (punto punto) en una URL. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR51234 http://www.ibm.com/support/docview.wss?uid=swg21692540 http://www.securitytracker.com/id/1031379 https://exchange.xforce.ibmcloud.com/vulnerabilities/98518 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 4.3EPSS: 0%CPEs: 14EXPL: 0

IBM WebSphere Process Server 7.0, WebSphere Enterprise Service Bus 7.0, and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 disregard the SSL setting in the SCA module HTTP import binding and unconditionally select the SSLv3 protocol, which makes it easier for remote attackers to hijack sessions or obtain sensitive information by leveraging the use of a weak cipher. IBM WebSphere Process Server 7.0, WebSphere Enterprise Service Bus 7.0, y Business Process Manager Advanced 7.5.x hasta 7.5.1.2, 8.0.x hasta 8.0.1.3, y 8.5.x hasta 8.5.5 desatienden la configuración SSL setting en el enlace de importación de HTTP del módulo SCA y seleccionan incondicionalmente el protocolo SSLv3, lo que facilita a atacantes remotos secuestrar sesiones o obtener información sensible a través del aprovechamiento del uso de un cifrado débil. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR51593 http://www-01.ibm.com/support/docview.wss?uid=swg21690780 http://www.securitytracker.com/id/1031382 http://www.securitytracker.com/id/1031383 https://exchange.xforce.ibmcloud.com/vulnerabilities/98488 • CWE-310: Cryptographic Issues •

CVSS: 4.3EPSS: 0%CPEs: 12EXPL: 0

Cross-site scripting (XSS) vulnerability in the redirect-login feature in IBM Business Process Manager (BPM) Advanced 7.5 through 8.5.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. Vulnerabilidad de XSS en la caracteristica redirect-login en IBM Business Process Manager (BPM) Advanced 7.5 hasta 8.5.5 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de una URL manipulada. • http://secunia.com/advisories/61804 http://www-01.ibm.com/support/docview.wss?uid=swg1JR51211 http://www-01.ibm.com/support/docview.wss?uid=swg1JR51507 http://www-01.ibm.com/support/docview.wss?uid=swg21687967 https://exchange.xforce.ibmcloud.com/vulnerabilities/96024 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.0EPSS: 0%CPEs: 8EXPL: 0

The Saved Search Admin component in the Process Admin Console in IBM Business Process Manager (BPM) 8.0 through 8.5.5 does not properly restrict task and instance listings in result sets, which allows remote authenticated users to bypass authorization checks and obtain sensitive information by executing a saved search. El componente Saved Search Admin en la consola Process Admin en IBM Business Process Manager (BPM) 8.0 hasta 8.5.5 no restringe debidamente los listados de tareas y instancias en las configuraciones de los resultados, lo que permite a usuarios remotos autenticados evadir las comprobaciones de autenticación y obtener información sensible mediante la ejecución de una búsqueda guardada. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR50984 http://www-01.ibm.com/support/docview.wss?uid=swg21684771 https://exchange.xforce.ibmcloud.com/vulnerabilities/95304 • CWE-264: Permissions, Privileges, and Access Controls •