First published: Mon Feb 29 2016(Updated: )
Cross-site scripting (XSS) vulnerability in Process Portal in IBM Business Process Manager 8.5.0.x through 8.5.0.2, 8.5.5.x through 8.5.5.0, and 8.5.6.x through 8.5.6.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Business Process Manager | =8.5.0.0 | |
IBM Business Process Manager | =8.5.0.0 | |
IBM Business Process Manager | =8.5.0.0 | |
IBM Business Process Manager | =8.5.0.1 | |
IBM Business Process Manager | =8.5.0.1 | |
IBM Business Process Manager | =8.5.0.1 | |
IBM Business Process Manager | =8.5.0.2 | |
IBM Business Process Manager | =8.5.0.2 | |
IBM Business Process Manager | =8.5.0.2 | |
IBM Business Process Manager | =8.5.5.0 | |
IBM Business Process Manager | =8.5.5.0 | |
IBM Business Process Manager | =8.5.5.0 | |
IBM Business Process Manager | =8.5.6.0 | |
IBM Business Process Manager | =8.5.6.0 | |
IBM Business Process Manager | =8.5.6.0 | |
IBM Business Process Manager | =8.5.6.2 | |
IBM Business Process Manager | =8.5.6.2 | |
IBM Business Process Manager | =8.5.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8524 is considered a high-severity cross-site scripting (XSS) vulnerability.
To fix CVE-2015-8524, upgrade to a patched version of IBM Business Process Manager that addresses this vulnerability.
CVE-2015-8524 affects users of IBM Business Process Manager versions from 8.5.0.0 to 8.5.6.2.
Attackers exploiting CVE-2015-8524 can inject arbitrary web scripts or HTML into affected applications.
Yes, CVE-2015-8524 can be exploited remotely through a crafted URL.