Page 6 of 84 results (0.010 seconds)

CVSS: 5.4EPSS: 0%CPEs: 4EXPL: 0

05 Oct 2016 — Cross-site scripting (XSS) vulnerability in a test page in IBM Business Process Manager Advanced 8.5.6.0 through 8.5.7.0 before cumulative fix 2016.09 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en una página de prueba en IBM Business Process Manager Advanced 8.5.6.0 hasta la versión 8.5.7.0 anterior al arreglo acumulativo 2016.09 permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través... • http://www-01.ibm.com/support/docview.wss?uid=swg1JR56391 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.5EPSS: 0%CPEs: 2EXPL: 0

30 Jun 2016 — IBM Business Process Manager 8.5.6 through 8.5.6.2 and 8.5.7 before 8.5.7.CF201606 allows remote authenticated users to bypass intended access restrictions and update process-instance variables via a REST API call. IBM Business Process Manager 8.5.6 hasta la versión 8.5.6.2 y 8.5.7 en versiones anteriores a 8.5.7.CF201606 permite a usuarios remotos autenticados eludir las restricciones destinadas al acceso y actualizar variables de instancia de proceso a través de una llamada API REST. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR55701 • CWE-284: Improper Access Control •

CVSS: 4.3EPSS: 0%CPEs: 31EXPL: 0

21 Mar 2016 — Business Space in IBM WebSphere Process Server 6.1.2.0 through 7.0.0.5 and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0.x through 8.5.0.2, 8.5.5.x through 8.5.5.0, and 8.5.6.x through 8.5.6.2 allows remote authenticated users to bypass intended access restrictions and create an arbitrary page or space via unspecified vectors. Business Space en IBM WebSphere Process Server 6.1.2.0 hasta la versión 7.0.0.5 y Business Process Manager Advanced 7.5.x hasta la versión 7.5.... • http://www-01.ibm.com/support/docview.wss?uid=swg1JR54678 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 5.4EPSS: 0%CPEs: 33EXPL: 0

03 Mar 2016 — Cross-site scripting (XSS) vulnerability in the document-list control implementation in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.2, and 8.5.5 and 8.5.6 through 8.5.6.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. Vulnerabilidad de XSS en la implementación de control del documento-listado en IBM Business Process Manager (BPM) 8.0 hasta la versión 8.0.1.3, 8.5.0 hasta la versión 8.5.0.2 y 8.5.5 y 8.5.6 hasta la versión 8.5.6.2 p... • http://www-01.ibm.com/support/docview.wss?uid=swg1JR55152 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 18EXPL: 0

29 Feb 2016 — Cross-site scripting (XSS) vulnerability in Process Portal in IBM Business Process Manager 8.5.0.x through 8.5.0.2, 8.5.5.x through 8.5.5.0, and 8.5.6.x through 8.5.6.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. Vulnerabilidad de XSS en Process Portal en IBM Business Process Manager 8.5.0.x hasta la versión 8.5.0.2, 8.5.5.x hasta la versión 8.5.5.0 y 8.5.6.x hasta la versión 8.5.6.2 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a tr... • http://www-01.ibm.com/support/docview.wss?uid=swg1JR54981 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.8EPSS: 0%CPEs: 54EXPL: 0

01 Jan 2016 — Remote Artifact Loader (RAL) in IBM WebSphere Process Server 7 and Business Process Manager Advanced 7.5 through 7.5.1.2, 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.2, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.2 does not properly use SSL for its HTTPS connection, which allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors. Remote Artifact Loader (RAL) en IBM WebSphere Process Server 7 y Business Process Manager Advanced 7.5 hasta la versión 7.5.1.2, 8.0 ... • http://www-01.ibm.com/support/docview.wss?uid=swg1JR54760 • CWE-17: DEPRECATED: Code •

CVSS: 5.4EPSS: 0%CPEs: 35EXPL: 0

03 Oct 2015 — Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 before 8.5.6.0 CF1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. Vulnerabilidad de XSS en IBM Business Process Manager (BPM) 8.0.x hasta la versión 8.0.1.3, 8.5.0 hasta la versión 8.5.0.1, 8.5.5 hasta la versión 8.5.5.0 y 8.5.6 en versiones anteriores a 8.5.6.0 CF1 permite a usuarios remotos autenticados in... • http://www-01.ibm.com/support/docview.wss?uid=swg1JR52696 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.1EPSS: 0%CPEs: 27EXPL: 0

01 Aug 2015 — IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0, when external Enterprise Content Management (ECM) integration is enabled with a certain technical system account configuration, allows remote authenticated users to bypass intended document-access restrictions via a (1) upload or (2) download action. Vulnerabilidad en IBM Business Process Manager (BPM) 8.0.x hasta la versión 8.0.1.3, 8.5.0 hasta la versión 8.5.0.1, 8.5.5 hasta l... • http://www-01.ibm.com/support/docview.wss?uid=swg1JR53209 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 6.5EPSS: 0%CPEs: 51EXPL: 0

21 Jul 2015 — The REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0 allows remote authenticated users to bypass intended access restrictions on task-variable value changes via unspecified vectors. Vulnerabilidad en la REST API en IBM Business Process Manager (BPM) en sus versiones 7.5.x hasta la 7.5.1.2, 8.0.x hasta la 8.0.1.3, 8.5.0 hasta la 8.5.0.1, 8.5.5 hasta la 8.5.5.0 y 8.5.6 hasta la 8.5.6.0 permite a... • http://www-01.ibm.com/support/docview.wss?uid=swg1JR52772 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 5.4EPSS: 0%CPEs: 55EXPL: 0

21 Jul 2015 — Cross-site scripting (XSS) vulnerability in the REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. Vulnerabilidad de XSS en la REST API en IBM Business Process Manager (BPM) en sus versiones 7.5.x hasta la 7.5.1.2, 8.0.x hasta la 8.0.1.3, 8.5.0 hasta la 8.5.0.1, 8.5.5 hasta la 8.5.5.0 y 8.5.6 hasta la 8.5... • http://www-01.ibm.com/support/docview.wss?uid=swg1JR52772 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •