PT-2017-6425 · Ibm · Ibm Business Process Manager Standard+2
Publicado
2017-08-28
·
Atualizado
2017-09-08
·
CVE-2015-0101
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Business Process Manager Standard versions 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5
IBM Business Process Manager Express versions 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5
IBM Business Process Manager Advanced versions 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5
Description
The issue is related to a cross-site scripting (XSS) vulnerability. This type of vulnerability allows an attacker to inject malicious scripts into content from otherwise trusted websites.
Recommendations
For IBM Business Process Manager Standard versions 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5, update to version 7.5, 8.0.1, or 8.5.5 or later.
For IBM Business Process Manager Express versions 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5, update to version 7.5, 8.0.1, or 8.5.5 or later.
For IBM Business Process Manager Advanced versions 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5, update to version 7.5, 8.0.1, or 8.5.5 or later.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Business Process Manager Advanced
Ibm Business Process Manager Express
Ibm Business Process Manager Standard