CVE-2015-1906: XSS
Cross-site scripting (XSS) vulnerability in the REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1906?
CVE-2015-1906 is classified as a medium severity vulnerability.
How do I fix CVE-2015-1906?
To fix CVE-2015-1906, apply the appropriate patches provided by IBM for your version of Business Process Manager.
What versions of IBM Business Process Manager are affected by CVE-2015-1906?
CVE-2015-1906 affects IBM Business Process Manager versions 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.0 through 8.5.6.0.
Can CVE-2015-1906 be exploited remotely?
Yes, CVE-2015-1906 can be exploited by remote authenticated users to inject arbitrary web script or HTML.
What type of vulnerability is CVE-2015-1906?
CVE-2015-1906 is a cross-site scripting (XSS) vulnerability.