Vulnerability Bulletins

IBM Security Bulletin: Cross-site scripting vulnerabilities in IBM Business Process Manager (BPM) Coach NG framework (CVE-2015-0158)

   
Affected software IBM
 
IBM Business Process Manager Coach NG framework is vulnerable to cross-site scripting, which is caused by the improper validation of user-supplied input. A remote attacker might exploit this vulnerability using a specially crafted URL to execute a script in a users web browser within the security context of the hosting web site after the URL is clicked. An attacker might use this vulnerability to steal the users cookie-based authentication credentials. CVE(s): CVE-2015-0158 Affected

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_cross_site_scripting_vulnerabilities_in_ibm_business_process_manager_bpm_coach_ng_framework_cve_2015_0158?lang=en_us