First published: Tue Mar 24 2015(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 and WebSphere Lombardi Edition (WLE) 7.2.x through 7.2.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Websphere Application Server | =7.1 | |
Ibm Websphere Application Server | =7.2 | |
Ibm Websphere Application Server | =7.2.0.1 | |
Ibm Websphere Application Server | =7.2.0.2 | |
Ibm Websphere Application Server | =7.2.0.3 | |
Ibm Websphere Application Server | =7.2.0.4 | |
Ibm Websphere Application Server | =7.2.0.5 | |
IBM Business Process Manager | =7.5.0.0 | |
IBM Business Process Manager | =7.5.0.0 | |
IBM Business Process Manager | =7.5.0.0 | |
IBM Business Process Manager | =7.5.0.1 | |
IBM Business Process Manager | =7.5.0.1 | |
IBM Business Process Manager | =7.5.0.1 | |
IBM Business Process Manager | =7.5.1.0 | |
IBM Business Process Manager | =7.5.1.0 | |
IBM Business Process Manager | =7.5.1.0 | |
IBM Business Process Manager | =7.5.1.1 | |
IBM Business Process Manager | =7.5.1.1 | |
IBM Business Process Manager | =7.5.1.1 | |
IBM Business Process Manager | =7.5.1.2 | |
IBM Business Process Manager | =7.5.1.2 | |
IBM Business Process Manager | =7.5.1.2 | |
IBM Business Process Manager | =8.0.0.0 | |
IBM Business Process Manager | =8.0.0.0 | |
IBM Business Process Manager | =8.0.0.0 | |
IBM Business Process Manager | =8.0.1.0 | |
IBM Business Process Manager | =8.0.1.0 | |
IBM Business Process Manager | =8.0.1.0 | |
IBM Business Process Manager | =8.0.1.1 | |
IBM Business Process Manager | =8.0.1.1 | |
IBM Business Process Manager | =8.0.1.1 | |
IBM Business Process Manager | =8.0.1.2 | |
IBM Business Process Manager | =8.0.1.2 | |
IBM Business Process Manager | =8.0.1.2 | |
IBM Business Process Manager | =8.0.1.3 | |
IBM Business Process Manager | =8.0.1.3 | |
IBM Business Process Manager | =8.0.1.3 | |
IBM Business Process Manager | =8.5.0.0 | |
IBM Business Process Manager | =8.5.0.0 | |
IBM Business Process Manager | =8.5.0.0 | |
IBM Business Process Manager | =8.5.0.1 | |
IBM Business Process Manager | =8.5.0.1 | |
IBM Business Process Manager | =8.5.0.1 | |
IBM Business Process Manager | =8.5.5.0 | |
IBM Business Process Manager | =8.5.5.0 | |
IBM Business Process Manager | =8.5.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0106 has a medium severity rating due to its potential for attackers to exploit cross-site scripting vulnerabilities.
To fix CVE-2015-0106, upgrade to the patched versions of IBM Business Process Manager and WebSphere Lombardi Edition as recommended by IBM.
CVE-2015-0106 affects IBM Business Process Manager versions 7.5.x to 8.5.5.0 and WebSphere Lombardi Edition versions 7.2.x to 7.2.0.5.
CVE-2015-0106 is classified as a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.
Organizations using the affected versions of IBM Business Process Manager and WebSphere Lombardi Edition are at risk from CVE-2015-0106.