Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Filtered by product Business Process Manager
Total 88 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-1674 1 Ibm 2 Business Automation Workflow, Business Process Manager 2024-11-21 6.5 MEDIUM 6.3 MEDIUM
IBM Business Process Manager 8.5 through 8.6 and 18.0.0.0 through 18.0.0.1 are vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 145109.
CVE-2018-1384 1 Ibm 4 Business Process Manager, Business Process Manager Enterprise Service Bus, Websphere Enterprise Service Bus and 1 more 2024-11-21 3.5 LOW 5.4 MEDIUM
IBM Business Process Manager 8.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138135.
CVE-2017-1769 1 Ibm 1 Business Process Manager 2024-11-21 6.8 MEDIUM 8.8 HIGH
IBM Business Process Manager 8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 136783.
CVE-2017-1767 1 Ibm 1 Business Process Manager 2024-11-21 3.5 LOW 5.4 MEDIUM
IBM Business Process Manager 8.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 136152.
CVE-2017-1766 1 Ibm 1 Business Process Manager 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
Due to incorrect authorization in IBM Business Process Manager 8.6 an attacker can claim and work on ad hoc tasks he is not assigned to. IBM X-Force ID: 136151.
CVE-2017-1765 1 Ibm 2 Business Process Manager, Business Process Manager Enterprise Service Bus 2024-11-21 4.0 MEDIUM 3.1 LOW
IBM Business Process Manager 8.6 could allow an authenticated user with special privileges to reveal sensitive information about the application server. IBM X-Force ID: 136150.
CVE-2017-1756 1 Ibm 3 Business Process Manager, Business Process Manager Enterprise Service Bus, Websphere 2024-11-21 2.1 LOW 4.0 MEDIUM
IBM Business Process Manager 8.6 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 135856.
CVE-2015-7463 1 Ibm 1 Business Process Manager 2024-11-21 5.5 MEDIUM 4.3 MEDIUM
IBM Business Process Manager 7.5.x, 8.0.x, 8.5.0, 8.5.5, and 8.5.6.0 through cumulative fix 2 allow remote authenticated users to delete process and task data by leveraging incorrect authorization checks. IBM X-Force ID: 108393.