Vulnerability Bulletins |
IBM Security Bulletin: Cross-site scripting vulnerability in IBM Business Process Manager (BPM) and WebSphere Lombardi Edition (WLE) Process Portal (CVE-2015-0106) |
|
| Affected software | IBM |
|
IBM Business Process Manager and WebSphere Lombardi Edition are vulnerable to cross-site scripting, which is caused by the improper validation of user-supplied input. A remote attacker might exploit this vulnerability using a specially crafted URL to execute a script in a users web browser within the security context of the hosting web site after the URL is clicked. An attacker might use this vulnerability to steal the users cookie-based authentication credentials. CVE(s): CVE-2015-0106 More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_cross_site_scripting_vulnerability_in_ibm_business_process_manager_bpm_and_websphere_lombardi_edition_wle_process_portal_cve_2015_0106?lang=en_us |
|






