Cross-Site Scripting in IBM Business Process Manager
CVE-2017-1425

5.4MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
26 September 2017

Summary

IBM Business Process Manager versions 8.0.1.1 and 8.5.7 are affected by a cross-site scripting vulnerability, enabling attackers to inject arbitrary JavaScript into the web user interface. This flaw allows for alteration of intended functionality, which could lead to the disclosure of sensitive credentials during trusted sessions. The risk associated with this vulnerability underscores the importance of secure coding practices and regular updates to application security.

Affected Version(s)

Business Process Manager Advanced 8.0.1.1

Business Process Manager Advanced 8.5.7

Business Process Manager Advanced 8.5.7.CF201609

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.