First published: Mon Aug 28 2017(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager Standard 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5; IBM Business Process Manager Express 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5; and IBM Business Process Manager Advanced 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Business Process Manager | =7.5 | |
IBM Business Process Manager | =7.5.0.1 | |
IBM Business Process Manager | =7.5.1 | |
IBM Business Process Manager | =7.5.1.1 | |
IBM Business Process Manager | =7.5.1.2 | |
IBM Business Process Manager | =8.0 | |
IBM Business Process Manager | =8.0.1 | |
IBM Business Process Manager | =8.0.1.1 | |
IBM Business Process Manager | =8.0.1.2 | |
IBM Business Process Manager | =8.0.1.3 | |
IBM Business Process Manager | =8.5 | |
IBM Business Process Manager | =8.5.0.1 | |
IBM Business Process Manager | =8.5.5 | |
IBM Business Process Manager | =7.5 | |
IBM Business Process Manager | =7.5.0.1 | |
IBM Business Process Manager | =7.5.1 | |
IBM Business Process Manager | =7.5.1.1 | |
IBM Business Process Manager | =7.5.1.2 | |
IBM Business Process Manager | =8.0 | |
IBM Business Process Manager | =8.0.1 | |
IBM Business Process Manager | =8.0.1.1 | |
IBM Business Process Manager | =8.0.1.2 | |
IBM Business Process Manager | =8.0.1.3 | |
IBM Business Process Manager | =8.5 | |
IBM Business Process Manager | =8.5.0.1 | |
IBM Business Process Manager | =8.5.5 | |
IBM Business Process Manager | =7.5 | |
IBM Business Process Manager | =7.5.0.1 | |
IBM Business Process Manager | =7.5.1 | |
IBM Business Process Manager | =7.5.1.1 | |
IBM Business Process Manager | =7.5.1.2 | |
IBM Business Process Manager | =8.0 | |
IBM Business Process Manager | =8.0.1 | |
IBM Business Process Manager | =8.0.1.1 | |
IBM Business Process Manager | =8.0.1.2 | |
IBM Business Process Manager | =8.0.1.3 | |
IBM Business Process Manager | =8.5 | |
IBM Business Process Manager | =8.5.0.1 | |
IBM Business Process Manager | =8.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0101 is classified as a medium severity cross-site scripting vulnerability affecting various versions of IBM Business Process Manager.
To fix CVE-2015-0101, you should upgrade to IBM Business Process Manager versions 7.5.5, 8.0.1, or 8.5.5 or later.
The affected versions for CVE-2015-0101 are IBM Business Process Manager Standard, Express, and Advanced versions prior to 7.5.5, 8.0.1, and 8.5.5.
Yes, CVE-2015-0101 can be exploited remotely through crafted requests that inject malicious scripts into the application.
CVE-2015-0101 can lead to cross-site scripting (XSS) attacks, allowing attackers to execute arbitrary scripts in the context of a user's browser.