XSS Vulnerability in IBM Business Process Manager and WebSphere Lombardi Edition
CVE-2014-3075
Currently unrated
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 4 September 2014
Summary
A Cross-site Scripting (XSS) vulnerability exists in IBM Business Process Manager versions 7.5.x to 8.5.5 and WebSphere Lombardi Edition version 7.2.0.x. This security flaw allows an attacker who is a remote authenticated user to upload malicious files, potentially injecting arbitrary web scripts or HTML into compromised applications. This vulnerability may enable attackers to execute harmful scripts in the context of other users, leading to unauthorized data access and manipulation across affected systems.
References
Timeline
Vulnerability published
Vulnerability Reserved