XSS Vulnerability in IBM Business Process Manager and WebSphere Lombardi Edition
CVE-2014-3075

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
4 September 2014

Summary

A Cross-site Scripting (XSS) vulnerability exists in IBM Business Process Manager versions 7.5.x to 8.5.5 and WebSphere Lombardi Edition version 7.2.0.x. This security flaw allows an attacker who is a remote authenticated user to upload malicious files, potentially injecting arbitrary web scripts or HTML into compromised applications. This vulnerability may enable attackers to execute harmful scripts in the context of other users, leading to unauthorized data access and manipulation across affected systems.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.