CVE-2016-0227: XSS
Cross-site scripting (XSS) vulnerability in the document-list control implementation in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.2, and 8.5.5 and 8.5.6 through 8.5.6.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0227?
CVE-2016-0227 is rated as medium severity due to its potential for cross-site scripting attacks.
How do I fix CVE-2016-0227?
To fix CVE-2016-0227, apply the latest security updates provided by IBM for affected versions of Business Process Manager.
Which versions of IBM Business Process Manager are affected by CVE-2016-0227?
CVE-2016-0227 affects IBM Business Process Manager versions 8.0 through 8.0.1.3 and versions 8.5.0 through 8.5.6.2.
What kind of attack can CVE-2016-0227 facilitate?
CVE-2016-0227 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary web scripts or HTML.
Who can exploit the vulnerability in CVE-2016-0227?
CVE-2016-0227 can be exploited by remote authenticated users who can craft malicious URLs.