CVE-2015-0101: XSS
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager Standard 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5; IBM Business Process Manager Express 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5; and IBM Business Process Manager Advanced 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0101?
CVE-2015-0101 is classified as a medium severity cross-site scripting vulnerability affecting various versions of IBM Business Process Manager.
How do I fix CVE-2015-0101?
To fix CVE-2015-0101, you should upgrade to IBM Business Process Manager versions 7.5.5, 8.0.1, or 8.5.5 or later.
What are the affected IBM Business Process Manager versions for CVE-2015-0101?
The affected versions for CVE-2015-0101 are IBM Business Process Manager Standard, Express, and Advanced versions prior to 7.5.5, 8.0.1, and 8.5.5.
Can CVE-2015-0101 be exploited remotely?
Yes, CVE-2015-0101 can be exploited remotely through crafted requests that inject malicious scripts into the application.
What types of attacks are possible with CVE-2015-0101?
CVE-2015-0101 can lead to cross-site scripting (XSS) attacks, allowing attackers to execute arbitrary scripts in the context of a user's browser.