CVE-2014-0957

IBM Business Process Manager - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in IBM Business Process Manager 7.5 through 8.5.5, and WebSphere Lombardi Edition 7.2, allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers a service failure.

Scores

EPSS 0.0028
EPSS Percentile 51.0%

Details

CWE
CWE-79
Status published
Products (14)
ibm/business_process_manager
ibm/business_process_manager
ibm/business_process_manager
ibm/business_process_manager
ibm/business_process_manager
ibm/business_process_manager
ibm/business_process_manager
ibm/business_process_manager
ibm/business_process_manager
ibm/business_process_manager
... and 4 more
Published Jul 18, 2014
Tracked Since Feb 18, 2026