CVE-2015-0106: XSS
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 and WebSphere Lombardi Edition (WLE) 7.2.x through 7.2.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0106?
CVE-2015-0106 has a medium severity rating due to its potential for attackers to exploit cross-site scripting vulnerabilities.
How do I fix CVE-2015-0106?
To fix CVE-2015-0106, upgrade to the patched versions of IBM Business Process Manager and WebSphere Lombardi Edition as recommended by IBM.
What are the affected versions of CVE-2015-0106?
CVE-2015-0106 affects IBM Business Process Manager versions 7.5.x to 8.5.5.0 and WebSphere Lombardi Edition versions 7.2.x to 7.2.0.5.
What type of vulnerability is CVE-2015-0106?
CVE-2015-0106 is classified as a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.
Who is impacted by CVE-2015-0106?
Organizations using the affected versions of IBM Business Process Manager and WebSphere Lombardi Edition are at risk from CVE-2015-0106.