
CVE-2018-1384
https://notcve.org/view.php?id=CVE-2018-1384
30 Mar 2018 — IBM Business Process Manager 8.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138135. IBM Business Process Manager 8.6 es vulnerable a Cross-Site Scripting. Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que altera las funcionalidades prev... • http://www.ibm.com/support/docview.wss?uid=swg22012604 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2015-0110
https://notcve.org/view.php?id=CVE-2015-0110
15 Sep 2017 — IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka WLE) 7.2.x allow remote authenticated users to bypass intended access restrictions on internal service types via vectors involving the executeServiceByName URL. IBM Business Process Manager (BPM) 7.5.x, 8.0.x y 8.5.x y WebSphere Lombardi Edition (WLE) 7.2.x permiten que usuarios autenticados remotos omitan las restricciones de acceso establecidas en tipos de servicios internos mediante vectores relacionados co... • http://www.securityfocus.com/bid/73274 • CWE-284: Improper Access Control •

CVE-2015-7454
https://notcve.org/view.php?id=CVE-2015-7454
21 Mar 2016 — Business Space in IBM WebSphere Process Server 6.1.2.0 through 7.0.0.5 and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0.x through 8.5.0.2, 8.5.5.x through 8.5.5.0, and 8.5.6.x through 8.5.6.2 allows remote authenticated users to bypass intended access restrictions and create an arbitrary page or space via unspecified vectors. Business Space en IBM WebSphere Process Server 6.1.2.0 hasta la versión 7.0.0.5 y Business Process Manager Advanced 7.5.x hasta la versión 7.5.... • http://www-01.ibm.com/support/docview.wss?uid=swg1JR54678 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2015-7441
https://notcve.org/view.php?id=CVE-2015-7441
01 Jan 2016 — Remote Artifact Loader (RAL) in IBM WebSphere Process Server 7 and Business Process Manager Advanced 7.5 through 7.5.1.2, 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.2, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.2 does not properly use SSL for its HTTPS connection, which allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors. Remote Artifact Loader (RAL) en IBM WebSphere Process Server 7 y Business Process Manager Advanced 7.5 hasta la versión 7.5.1.2, 8.0 ... • http://www-01.ibm.com/support/docview.wss?uid=swg1JR54760 • CWE-17: DEPRECATED: Code •

CVE-2015-0106
https://notcve.org/view.php?id=CVE-2015-0106
24 Mar 2015 — Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 and WebSphere Lombardi Edition (WLE) 7.2.x through 7.2.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. Vulnerabilidad de XSS en IBM Business Process Manager (BPM) 7.5.x hasta 7.5.1.2, 8.0 hasta 8.0.1.3, 8.5.0 hasta 8.5.0.1, y 8.5.5 hasta 8.5.5.0 y WebSphere Lombardi Edition (WLE) 7.2.x hasta 7.2.0.5 p... • http://www-01.ibm.com/support/docview.wss?uid=swg1JR50795 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-6176
https://notcve.org/view.php?id=CVE-2014-6176
16 Dec 2014 — IBM WebSphere Process Server 7.0, WebSphere Enterprise Service Bus 7.0, and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 disregard the SSL setting in the SCA module HTTP import binding and unconditionally select the SSLv3 protocol, which makes it easier for remote attackers to hijack sessions or obtain sensitive information by leveraging the use of a weak cipher. IBM WebSphere Process Server 7.0, WebSphere Enterprise Service Bus 7.0, y Business Proc... • http://www-01.ibm.com/support/docview.wss?uid=swg1JR51593 • CWE-310: Cryptographic Issues •

CVE-2014-4758
https://notcve.org/view.php?id=CVE-2014-4758
04 Sep 2014 — IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow remote authenticated users to bypass intended access restrictions and send requests to internal services via a callService URL. IBM Business Process Manager (BPM) 7.5.x hasta 8.5.5 y WebSphere Lombardi Edition 7.2.x permiten a usuarios remotos autenticados evadir las restricciones de acceso y enviar solicitudes a los servicios internos a través de una URL callService. • http://secunia.com/advisories/60851 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2014-3075
https://notcve.org/view.php?id=CVE-2014-3075
04 Sep 2014 — Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.0.x allows remote authenticated users to inject arbitrary web script or HTML via an uploaded file. Vulnerabilidad de XSS en IBM Business Process Manager (BPM) 7.5.x hasta 8.5.5 y WebSphere Lombardi Edition 7.2.0.x permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través de un fichero subido. • http://www-01.ibm.com/support/docview.wss?uid=swg1JR50092 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-3087
https://notcve.org/view.php?id=CVE-2014-3087
17 Aug 2014 — callService.do in IBM Business Process Manager (BPM) 7.5 through 8.5.5 and WebSphere Lombardi Edition 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. callService.do en IBM Business Process Manager (BPM) 7.5 hasta 8.5.5 y WebSphere Lombardi Edition 7.2 hasta 7.2.0.5 permite a usuarios remotos autenticados leer ficheros arbitrarios a través de una declara... • http://secunia.com/advisories/60752 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2014-0957
https://notcve.org/view.php?id=CVE-2014-0957
18 Jul 2014 — Cross-site scripting (XSS) vulnerability in IBM Business Process Manager 7.5 through 8.5.5, and WebSphere Lombardi Edition 7.2, allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers a service failure. Vulnerabilidad de XSS en IBM Business Process Manager 7.5 hasta 8.5.5, y WebSphere Lombardi Edition 7.2, permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de una URL manipulada que provoca un fallo de servicio. • http://secunia.com/advisories/59557 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •