Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Prasath K

#20706de 53,640
12.2CVSS total
Vulnerabilidades · 2
Média
2
PT-2017-13323
5.4
2017-09-26
Ibm · Ibm Business Process Manager · CVE-2017-1425
**Name of the Vulnerable Software and Affected Versions** IBM Business Process Manager versions 8.0.1.1 through 8.5.7 **Description** The issue allows users to embed arbitrary JavaScript code in the Web UI, altering the intended functionality and potentially leading to credentials disclosure within a trusted session. **Recommendations** For versions 8.0.1.1 through 8.5.7, at the moment, there is no information about a newer version that contains a fix for this issue.
PT-2017-10270
6.8
2017-03-07
Ibm · Ibm Business Process Manager · CVE-2016-9693
**Name of the Vulnerable Software and Affected Versions** IBM Business Process Manager versions 7.5 through 8.5 **Description** The issue allows an attacker to cause an unauthenticated victim to download a malicious payload, potentially bypassing existing file type restrictions. This could lead to the payload being considered executable and causing damage on the victim's machine. **Recommendations** For IBM Business Process Manager versions 7.5 through 8.5, consider restricting the file download capability until a fix is available. As a temporary workaround, restrict access to the file download feature to minimize the risk of exploitation.