CVE-2017-1494: XSS
IBM Business Process Manager 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128692.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1494?
CVE-2017-1494 has a medium severity rating due to its potential for credential disclosure within trusted sessions.
How do I fix CVE-2017-1494?
To fix CVE-2017-1494, apply the latest security patches provided by IBM for affected versions of IBM Business Process Manager.
Which versions of IBM Business Process Manager are affected by CVE-2017-1494?
IBM Business Process Manager versions 8.5.5.0, 8.5.6.0, and 8.5.7.0 are affected by CVE-2017-1494.
Can CVE-2017-1494 lead to additional attacks?
Yes, CVE-2017-1494 can potentially allow for further exploitation such as phishing or session hijacking.
Is CVE-2017-1494 a common vulnerability?
CVE-2017-1494 is notable as it relates to cross-site scripting, which is a common class of vulnerabilities in web applications.