Cross-Site Scripting Vulnerability in IBM Business Process Manager and WebSphere Lombardi Edition
CVE-2014-0957 
Currently unrated
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 18 July 2014
What is CVE-2014-0957?
A Cross-Site Scripting (XSS) vulnerability exists in IBM Business Process Manager versions 7.5 to 8.5.5 and WebSphere Lombardi Edition 7.2. Attackers can exploit this vulnerability by injecting arbitrary web scripts or HTML via specially crafted URLs. This manipulation can lead to service failures, allowing for unauthorized actions or data exposure to occur within the affected web applications.