First published: Fri Dec 19 2014(Updated: )
Cross-site scripting (XSS) vulnerability in the Process Inspector in IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3 and 8.5.x through 8.5.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Business Process Manager | =8.0.0.0 | |
IBM Business Process Manager | =8.0.1.0 | |
IBM Business Process Manager | =8.0.1.1 | |
IBM Business Process Manager | =8.0.1.2 | |
IBM Business Process Manager | =8.0.1.3 | |
IBM Business Process Manager | =8.5.0.0 | |
IBM Business Process Manager | =8.5.0.1 | |
IBM Business Process Manager | =8.5.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6173 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
To fix CVE-2014-6173, upgrade to the latest patched version of IBM Business Process Manager.
CVE-2014-6173 affects remote authenticated users of IBM Business Process Manager versions between 8.0.x and 8.5.x.
CVE-2014-6173 is a cross-site scripting (XSS) vulnerability allowing injection of arbitrary web script or HTML.
Yes, CVE-2014-6173 can be exploited remotely by authenticated users through crafted URLs.