Page 9 of 84 results (0.005 seconds)

CVSS: 5.4EPSS: 0%CPEs: 72EXPL: 0

IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130409. Las versiones 7.5, 8.0 y 8.5 de IBM Business Process Manager son vulnerables a Cross-Site Scripting. Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que altera las funcionalidades planeadas. • http://www.ibm.com/support/docview.wss?uid=swg22007351 http://www.securityfocus.com/bid/100960 https://exchange.xforce.ibmcloud.com/vulnerabilities/130409 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 0

IBM Business Process Manager 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127477. IBM Business Process Manager 8.5.7 es vulnerable a Cross-Site Scripting. Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que altera las funcionalidades planeadas. • http://www.ibm.com/support/docview.wss?uid=swg22005112 http://www.securityfocus.com/bid/100962 https://exchange.xforce.ibmcloud.com/vulnerabilities/127477 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 2.5EPSS: 0%CPEs: 72EXPL: 0

IBM Business Process Manager 7.5, 8.0, and 8.5 temporarily stores files in a temporary folder during offline installs which could be read by a local user within a short timespan. IBM X-Force ID: 126461. IBM Business Process Manager 7.5, 8.0 y 8.5 guarda temporalmente los archivos en una carpeta temporal durante las instalaciones offline, los cuales podrían ser leídos por un usuario local en un corto espacio de tiempo. IBM X-Force ID: 126461. • http://www.ibm.com/support/docview.wss?uid=swg22004654 http://www.securityfocus.com/bid/100964 https://exchange.xforce.ibmcloud.com/vulnerabilities/126461 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •

CVSS: 6.5EPSS: 0%CPEs: 19EXPL: 0

IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka WLE) 7.2.x allow remote authenticated users to bypass intended access restrictions on internal service types via vectors involving the executeServiceByName URL. IBM Business Process Manager (BPM) 7.5.x, 8.0.x y 8.5.x y WebSphere Lombardi Edition (WLE) 7.2.x permiten que usuarios autenticados remotos omitan las restricciones de acceso establecidas en tipos de servicios internos mediante vectores relacionados con la URL executeServiceByName. • http://www.securityfocus.com/bid/73274 https://www-304.ibm.com/support/docview.wss?uid=swg21694940 • CWE-284: Improper Access Control •

CVSS: 6.1EPSS: 0%CPEs: 39EXPL: 0

Cross-site scripting (XSS) vulnerability in IBM Business Process Manager Standard 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5; IBM Business Process Manager Express 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5; and IBM Business Process Manager Advanced 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5. Existe una vulnerabilidad de tipo Cross-Site Scripting (XSS) en IBM Business Process Manager Standard 7.5.x anterior a la 7.5, 8.0.x anterior a la 8.0.1, 8.5.x anterior a la 8.5.5; IBM Business Process Manager Express 7.5.x anterior a la 7.5, 8.0.x anterior a la 8.0.1, 8.5.x anterior a la 8.5.5 y en IBM Business Process Manager Advanced 7.5.x anterior a la 7.5, 8.0.x anterior a la 8.0.1 y 8.5.x anterior a la 8.5.5. • http://www-01.ibm.com/support/docview.wss?uid=swg21693134 http://www.securityfocus.com/bid/72920 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •