LOW
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.6.0 and WebSphere Lombardi Edition (WLE) 7.2.x through 7.2.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL
Published May 25, 2015
3.5
LOWCVSS 2.0
EPSS 1.33%
Description
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.6.0 and WebSphere Lombardi Edition (WLE) 7.2.x through 7.2.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Affected products
No data.
Configuration 1
Configuration 2
OR
- 7.5.0.0
- 7.5.0.0
- 7.5.0.0
- 7.5.0.0
- 7.5.0.1
- 7.5.0.1
- 7.5.0.1
- 7.5.0.1
- 7.5.1.0
- 7.5.1.0
- 7.5.1.0
- 7.5.1.0
- 7.5.1.1
- 7.5.1.1
- 7.5.1.1
- 7.5.1.1
- 7.5.1.2
- 7.5.1.2
- 7.5.1.2
- 7.5.1.2
- 8.0.0.0
- 8.0.0.0
- 8.0.0.0
- 8.0.0.0
- 8.0.1.0
- 8.0.1.0
- 8.0.1.0
- 8.0.1.0
- 8.0.1.1
- 8.0.1.1
- 8.0.1.1
- 8.0.1.1
- 8.0.1.2
- 8.0.1.2
- 8.0.1.2
- 8.0.1.2
- 8.0.1.3
- 8.0.1.3
- 8.0.1.3
- 8.5.0.0
- 8.5.0.0
- 8.5.0.0
- 8.5.0.0
- 8.5.0.1
- 8.5.0.1
- 8.5.0.1
- 8.5.0.1
- 8.5.5.0
- 8.5.5.0
- 8.5.5.0
- 8.5.5.0
- 8.5.6.0
- 8.5.6.0
- 8.5.6.0
- 8.5.6.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT06812 vendor-advisoryx_refsource_AIXAPARPatchVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR52420 vendor-advisoryx_refsource_AIXAPARPatchVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21697120 x_refsource_CONFIRMPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www-01.ibm.com/support/docview.wss?uid=swg1IT06812 | vendor-advisoryx_refsource_AIXAPARPatchVendor Advisory | |
| http://www-01.ibm.com/support/docview.wss?uid=swg1JR52420 | vendor-advisoryx_refsource_AIXAPARPatchVendor Advisory | |
| http://www-01.ibm.com/support/docview.wss?uid=swg21697120 | x_refsource_CONFIRMPatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published May 25, 2015
Updated Aug 6, 2024
Reserved Nov 18, 2014
Link CVE-2015-0156
CISA Vulnrichment
Updated n/a