CVE-2013-0581: XSS
Multiple cross-site scripting (XSS) vulnerabilities in IBM Business Process Manager (BPM) 7.5.1.x, 8.0.0.x, and 8.0.1 before FP1 allow remote authenticated users to inject arbitrary web script or HTML via vectors involving (1) ProcessPortal/jsp/socialPortal/dashboard.jsp, (2) teamworks/executeServiceByName, (3) portal/jsp/viewAdHocReportWizard.do, or (4) rest/bpm/wle/v1/process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0581?
CVE-2013-0581 is classified as a medium severity vulnerability due to its ability to allow cross-site scripting attacks.
How do I fix CVE-2013-0581?
To fix CVE-2013-0581, it is recommended to update to the latest fix pack provided by IBM for affected versions of Business Process Manager.
What versions of IBM Business Process Manager are affected by CVE-2013-0581?
CVE-2013-0581 affects IBM Business Process Manager versions 7.5.1.x, 8.0.0.x, and 8.0.1 before FP1.
What type of vulnerabilities does CVE-2013-0581 involve?
CVE-2013-0581 involves multiple cross-site scripting (XSS) vulnerabilities.
Can remote authenticated users exploit CVE-2013-0581?
Yes, remote authenticated users can exploit CVE-2013-0581 to inject arbitrary web scripts or HTML.