Vulnerability Bulletins

IBM Security Bulletin: Cross-Site Scripting vulnerabilities in Dojo affect IBM Business Process Manager (BPM), WebSphere Lombardi Edition (WLE), and WebSphere Process Server (WPS) - CVE-2014-8917

   
Affected software IBM
 
Cross-Site scripting vulnerabilities been reported in Dojo affect IBM Business Process Manager (BPM), WebSphere Lombardi Edition (WLE), and WebSphere Process Server (WPS). CVE(s): CVE-2014-8917 Affected product(s) and affected version(s): WebSphere Process Server V7 WebSphere Lombardi Edition V7.2 IBM Business Process Manager V7.5 through V8.5.6 If you are using an earlier unsupported version of the above products, IBM strongly recommends updating to a supported version. Refer

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_cross_site_scripting_vulnerabilities_in_dojo_affect_ibm_business_process_manager_bpm_websphere_lombardi_edition_wle_and_websphere_process_server_wps_cve_2014_8917?lang=en_us